<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
>

<channel>
	<title>The Security Catalyst&#187; Podcast</title>
	<atom:link href="http://www.securitycatalyst.com/tag/podcast/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>Michael Santarcangelo delivers Awareness that Works™</description>
	<lastBuildDate>Tue, 06 Jul 2010 08:52:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<!-- podcast_generator="Blubrry PowerPress/1.0.9" mode="advanced" entry="normal" -->
	<itunes:summary>Michael J. Santarcangelo, II is a human catalyst. An expert who speaks on information protection â including compliance, privacy and awareness â Michael energizes and inspires his audiences to change the way they protect information. His passion and approach gets results that change behaviors. 

As the voice of optimism in an industry of doomsayers, Michael has recently completed his first book, Into the Breach (www.intothebreach.com), which provides the wisdom and answers executives need to defend their organization against breaches while discovering how to increase revenue, protect the bottom line and efficiently manage people, information and risk.

In this podcast series, Michael shares ideas, research and strategies for your success. 
</itunes:summary>
	<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/tsc_icon.png" />
	<itunes:owner>
		<itunes:name>Michael Santarcangelo | The Security Catalyst</itunes:name>
		<itunes:email>michael@securitycatalyst.com</itunes:email>
	</itunes:owner>
	<managingEditor>michael@securitycatalyst.com (Michael Santarcangelo | The Security Catalyst)</managingEditor>
	<copyright>Copyright 2009 The Security Catalyst. All Rights Reserved. </copyright>
	<itunes:subtitle>A catalyst for engaging, empowering and enabling individuals; turn insiders into allies who reduce business risk!</itunes:subtitle>
	<itunes:keywords>security, risk, privacy, compliance, breach, awareness, training, catalyst, confidentiality, integrity, availability, cissp, cism, cisa, cpp</itunes:keywords>
	<image>
		<title>The Security Catalyst&#187; Podcast</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
	<itunes:category text="Education" />
		<item>
		<title>Into the Breach – Audio Series – Chapter 5 (The Strategy to Protect Information)</title>
		<link>http://www.securitycatalyst.com/into-the-breach-audio-series-chapter-5/</link>
		<comments>http://www.securitycatalyst.com/into-the-breach-audio-series-chapter-5/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 21:23:18 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[emc]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[santarcangelo]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/into-the-breach-%e2%80%93-audio-series-%e2%80%93-chapter-5-the-strategy-to-protect-information/</guid>
		<description><![CDATA[Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today’s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Finto-the-breach-audio-series-chapter-5%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Finto-the-breach-audio-series-chapter-5%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the continuation of the <a href="http://www.securitycatalyst.com/innovation/into-the-breach/"><strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk</em></strong></a> audio series. <a href="http://www.securitycatalyst.com/buy-into-the-breach/">(Click this link) to learn more about this how this book solves today’s challenges and pick up a complete copy</a>.</p>
<p>This series, underwritten by <a href="http://www.configuresoft.com/securitycatalyst.aspx">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).</p>
<h3>What you’ll find in episode 6, Into the Breach: Chapter 5 (The Strategy to Protect Information)</h3>
<p>Chapter 5 is the introduction to Part II of Into the Breach &#8212; where the focus shifts to looking at what needs to be done. I outline a powerful, yet simple, approach dubbed &#8220;The Strategy to Protect Information.&#8221;</p>
<p>Key is the focus on information, not data, and the three steps that any organization must follow in order to be effective. The balance of Part II explains how &#8211; but just learning and understanding the three part strategy is transformative.</p>
<p>After listening to this chapter, you will know the strategy and be able to apply it to your current challenge &#8212; small and tactical or larger and organizational.</p>
<h3>Put the power of Into the Breach to work for you…</h3>
<p>After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li>Check out <a href="http://www.securitycatalyst.com/solutions/getting-started-with-awareness-that-works/">Awareness that Works™</a> – Michael Santarcangelo’s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Finto-the-breach-audio-series-chapter-5%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Finto-the-breach-audio-series-chapter-5%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/into-the-breach-audio-series-chapter-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://securitycatalyst.com/podcast/ITB-Santarcangelo-CHAPTER-5.mp3" length="13425894" type="audio/mpeg" />
			<itunes:keywords>breach,catalyst,emc,into the breach,Podcast,santarcangelo</itunes:keywords>
		<itunes:subtitle>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâs challenges and pick up a complete copy.</itunes:subtitle>
		<itunes:summary>Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves todayâs challenges and pick up a complete copy.

This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What youâll find in episode 6, Into the Breach: Chapter 5 (The Strategy to Protect Information)
Chapter 5 is the introduction to Part II of Into the Breach -- where the focus shifts to looking at what needs to be done. I outline a powerful, yet simple, approach dubbed &quot;The Strategy to Protect Information.&quot;

Key is the focus on information, not data, and the three steps that any organization must follow in order to be effective. The balance of Part II explains how - but just learning and understanding the three part strategy is transformative.

After listening to this chapter, you will know the strategy and be able to apply it to your current challenge -- small and tactical or larger and organizational.
Put the power of Into the Breach to work for youâ¦
After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	Check outÂ Awareness that Worksâ¢ â Michael Santarcangeloâs program to guide smart investment in people, with guaranteed results (this program pays for itself).
</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Into the Breach &#8211; Audio Series &#8211; The Introduction</title>
		<link>http://www.securitycatalyst.com/into-the-breach-audio-series-the-introduction/</link>
		<comments>http://www.securitycatalyst.com/into-the-breach-audio-series-the-introduction/#comments</comments>
		<pubDate>Sun, 05 Jul 2009 18:43:04 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[audio series]]></category>
		<category><![CDATA[configuresoft]]></category>
		<category><![CDATA[emc]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2037</guid>
		<description><![CDATA[Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Finto-the-breach-audio-series-the-introduction%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Finto-the-breach-audio-series-the-introduction%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png"><img class="alignleft size-full wp-image-2578" title="itb-audioseries-150px" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/itb-audioseries-150px.png" alt="" width="150" height="150" /></a>Welcome to the audio series of <strong><em>Into the Breach: Protect Your Business by Managing People, Information and Risk </em></strong>(<a href="http://www.securitycatalyst.com/into-the-breach/" target="_blank">click this link to learn more about this book</a>). This series, underwritten by <a href="http://configuresoft.com/" target="_blank">Configuresoft, now part of EMC</a>, is the full and unabridged audio version of <em>Into the Breach</em>, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the last Tuesday of each month (there are 13 chapters total).</p>
<h3>What you’ll find in this segment</h3>
<p>The Introduction explores the nature of the challenge faced by organizations around the world. As we prepare for the journey “Into the Breach”, it is revealed that breaches are only symptoms, and the real challenge is described as a human paradox. Setting the stage for a shift in thinking necessary to get results, three common myths are exposed and addressed. A powerful strategy to protect information is shared, and the clarion call to engage, empower and enable people is sounded.</p>
<h3>Put the power of Into the Breach to work for you…</h3>
<p>After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by</p>
<ol>
<li>Engage with Michael on twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>)</li>
<li>Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!</li>
<li>Check out <a href="http://www.securitycatalyst.com/solutions/getting-started-with-awareness-that-works/">Awareness that Works™</a> – Michael Santarcangelo’s program to guide smart investment in people, with guaranteed results (this program pays for itself).</li>
</ol>
<ol></ol>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Finto-the-breach-audio-series-the-introduction%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Finto-the-breach-audio-series-the-introduction%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/into-the-breach-audio-series-the-introduction/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/ITB-Santarcangelo-INTRODUCTION.mp3" length="9640278" type="audio/mpeg" />
			<itunes:keywords>audio series,configuresoft,emc,into the breach,Podcast,twitter</itunes:keywords>
		<itunes:subtitle>Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book). This series, underwritten by Configuresoft, now part of EMC,</itunes:subtitle>
		<itunes:summary>Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the last Tuesday of each month (there are 13 chapters total).
What youâll find in this segment
The Introduction explores the nature of the challenge faced by organizations around the world. As we prepare for the journey âInto the Breachâ, it is revealed that breaches are only symptoms, and the real challenge is described as a human paradox. Setting the stage for a shift in thinking necessary to get results, three common myths are exposed and addressed. A powerful strategy to protect information is shared, and the clarion call to engage, empower and enable people is sounded.
Put the power of Into the Breach to work for youâ¦
After listening to this segment ofÂ Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by

	Engage with Michael on twitter (http://twitter.com/catalyst)
	Subscribe to The Security Catalyst podcast &amp; blog to get more insights; ask a question and get an answer!
	Check outÂ Awareness that Worksâ¢ â Michael Santarcangeloâs program to guide smart investment in people, with guaranteed results (this program pays for itself).

</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>netcast for this week: I was the (surprise) guest host on the Netsec Podcast</title>
		<link>http://www.securitycatalyst.com/netcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast/</link>
		<comments>http://www.securitycatalyst.com/netcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast/#comments</comments>
		<pubDate>Thu, 03 Jul 2008 20:02:45 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[mckeay]]></category>
		<category><![CDATA[netsec podcast]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=466</guid>
		<description><![CDATA[One of the true benefits of sharing thoughts through spoken and written word is the ability to meet quality people. I thrive on conversation &#8211; especially discourse that leads to new understanding. I am a firm believer that through purposeful conversation, honest intentions and open minds we can solve a lot of challenges we face. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fnetcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fnetcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>One of the true benefits of sharing thoughts through spoken and written word is the ability to meet quality people. I thrive on conversation &#8211; especially discourse that leads to new understanding. I am a firm believer that through purposeful conversation, honest intentions and open minds we can solve a lot of challenges we face.</p>
<p>So when Martin McKeay and I were &#8220;chatting&#8221; online Tuesday night, he popped in with &#8220;Hey &#8211; no pressure, but do you want to cohost tonight?&#8221; It took about a minute to decide. He shared some links to stories to talk about and I took 30 minutes to read them and write down some ideas &#8211; and then boom &#8211; we recorded.</p>
<p>I really enjoyed the conversation and was really amped at the end. It took me a while to get ready for bed &#8211; my mind was still engaged. I hope you have a similar experience when listening!</p>
<p>Find the show notes here: <a href="http://netsecpodcast.com/?p=48">http://netsecpodcast.com/?p=48</a></p>
<p>And the direct link to the program here: <a href="http://media.libsyn.com/media/mckeay/nsp-070108-ep110.mp3">http://media.libsyn.com/media/mckeay/nsp-070108-ep110.mp3</a></p>
<p> </p>
<p>(PS: I hope you still chose to listen to the programming on The Security Catalyst; however, somewhere in the feedchange, we seem to have confused iTunes. If it doesn&#8217;t look like we have new shows &#8211; you may want to unsubscribe and resubscribe.)
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fnetcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fnetcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/netcast-for-this-week-i-was-the-surprise-guest-host-on-the-netsec-podcast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://media.libsyn.com/media/mckeay/nsp-070108-ep110.mp3" length="60824138" type="audio/mpeg" />
			<itunes:keywords>mckeay,netsec podcast,Podcast,security</itunes:keywords>
		<itunes:subtitle>One of the true benefits of sharing thoughts through spoken and written word is the ability to meet quality people. I thrive on conversation - especially discourse that leads to new understanding. I am a firm believer that through purposeful conversati...</itunes:subtitle>
		<itunes:summary>One of the true benefits of sharing thoughts through spoken and written word is the ability to meet quality people. I thrive on conversation - especially discourse that leads to new understanding. I am a firm believer that through purposeful conversation, honest intentions and open minds we can solve a lot of challenges we face.

So when Martin McKeay and I were &quot;chatting&quot; online Tuesday night, he popped in with &quot;Hey - no pressure, but do you want to cohost tonight?&quot; It took about a minute to decide. He shared some links to stories to talk about and I took 30 minutes to read them and write down some ideas - and then boom - we recorded.

I really enjoyed the conversation and was really amped at the end. It took me a while to get ready for bed - my mind was still engaged. I hope you have a similar experience when listening!

Find the show notes here:Â http://netsecpodcast.com/?p=48

And the direct link to the program here:Â http://media.libsyn.com/media/mckeay/nsp-070108-ep110.mp3

Â 

(PS: I hope you still chose to listen to the programming on The Security Catalyst; however, somewhere in the feedchange, we seem to have confused iTunes. If it doesn&#039;t look like we have new shows - you may want to unsubscribe and resubscribe.)</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst Show &#8211; Pop Culture Security (debut): Night at the Museum</title>
		<link>http://www.securitycatalyst.com/security-catalyst-show-pop-culture-security-debut-night-at-the-museum/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-show-pop-culture-security-debut-night-at-the-museum/#comments</comments>
		<pubDate>Wed, 28 May 2008 12:37:59 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[pop culture security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=452</guid>
		<description><![CDATA[Learn how to use Pop Culture to connect with those around you. This movie held many lessons for those responsible for security in addition to providing some excellent examples for us to anchor our points to. We will work to keep the program short, informative and useful - especially if you are interested in building a security awareness training program that works!]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-show-pop-culture-security-debut-night-at-the-museum%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-show-pop-culture-security-debut-night-at-the-museum%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Welcome to the debut of the Pop Culture Security program &#8211; a monthly installment of the Security Catalyst Show. Please also welcome James Costello &#8211; the man with the idea for this program and my cohost on this effort. This program explores and explains how to use pop culture to communicate security concepts to those around you. We explain by doing, and respond to your challenges.</p>
<p>This podcast is based, to a large extent, on the work James did in preparing for and delivering a peer to peer session at the RSA conference this year. While sitting at Mel&#8217;s the morning of his presentation, we enjoyed a conversation about the topic that kept on going, and immediately decided the best way to extend the conversation and build on his efforts was to produce a monthly program.</p>
<p>For our first piece of Pop Culture to use as a reference point to better explain security, we selected <a href="http://en.wikipedia.org/wiki/Night_at_the_Museum">Night at the Museum</a> &#8211; a comedy with Ben Stiller that is currently (or was) running on <a href="http://www.hbo.com/">Home Box Office (HBO</a>). </p>
<p>Movie at IMDB (including synopsis): http://www.imdb.com/title/tt0477347/</p>
<p>Movie Trailer: http://www.imdb.com/video/screenplay/vi2459500825/</p>
<p>This movie held many lessons for those responsible for security in addition to providing some excellent examples for us to anchor our points to. We will work to keep the program short, informative and useful &#8211; especially if you are interested in building a security awareness training program that works!</p>
<p>To participate in the monthly challenge:</p>
<ul>
<li>call  206-350-8346 and leave us a message with your challenge</li>
<li>email popculturesecurity &amp;at&amp; securitycatalyst dot com</li>
</ul>
<p> </p>
<p>PS: I recently purchased a snowball microphone in an effort to streamline my audio programs and preserve quality. So far, I am disappointed with the quality of the unit &#8211; and feel that my sound is hollow and tinny; as such, I&#8217;ll be exploring how to restore the sound quality I appreciate in the coming days. The challenge is capturing sound in a way that works with Skype for many of this interviews, but is still portable. If you have experiences, ideas and suggestions for something functional, portable and reliable &#8211; shoot me a note. In the meantime, enjoy the programs. More to come next week, with an &#8220;Author Interview.&#8221;
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-show-pop-culture-security-debut-night-at-the-museum%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-show-pop-culture-security-debut-night-at-the-museum%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-show-pop-culture-security-debut-night-at-the-museum/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>TSC May 21 2008 &#124; The Right Way to Address the Debian OpenSSL Vulnerability</title>
		<link>http://www.securitycatalyst.com/tsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability/</link>
		<comments>http://www.securitycatalyst.com/tsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability/#comments</comments>
		<pubDate>Wed, 21 May 2008 16:21:48 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[openSSL]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[venafi]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=449</guid>
		<description><![CDATA[During this program, Paul (from Venafi) and I start by exploring how to engage business users in the conversation. We progress to tactical and strategic ways to address this challenge while realizing this is an opportunity to make some improvements that bring better future results.

It comes from planning and following a process informed by experience – and we’ll share the insights with you in 30 minutes or less!]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Ftsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Ftsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><!--StartFragment--></p>
<p class="MsoNormal">It was disclosed last week that a vulnerability in the OpenSSL packages used by debian systems contained a flaw where random numbers were not actually random, paving the way for another attack vector.</p>
<p class="MsoNormal">Plenty of specific details and analysis can be found in different places, including:</p>
<p class="MsoNormal"><a href="http://wiki.debian.org/SSLkeys">http://wiki.debian.org/SSLkeys</a></p>
<p class="MsoNormal"><a href="http://www.us-cert.gov/cas/techalerts/TA08-137A.html">http://www.us-cert.gov/cas/techalerts/TA08-137A.html</a></p>
<p class="MsoNormal"><a href="http://www.kb.cert.org/vuls/id/925211">http://www.kb.cert.org/vuls/id/925211</a></p>
<p class="MsoNormal"><a href="http://secunia.com/advisories/30220/">http://secunia.com/advisories/30220/</a></p>
<p class="MsoNormal">For many, this signals the fire-drill of reaction and patching &#8212; just in time for a big holiday weekend (aka the “start of summer”) here in the United States.</p>
<p class="MsoNormal">Just days before this was announced, I was introduced to <a href="http://www.venafi.com/">Venafi</a> (as a direct result of my press pass at RSA). During the conversation, I realized they really own the niche of Systems Management for Encryption. As we shared a lively and informative conversation, I was reminded that SSL is not just something we stick on web servers; it goes deeper and wider in many enterprises today. As soon as you have to manage many of these encrypted connections, the process gains some complication – and is ripe for error. Step in Venafi.</p>
<p class="MsoNormal">When the debian vulnerability was announced, I immediately asked if Venafi would be willing to share some insights about how organizations <em>should</em> be handling this issue. This is bigger than patching (remember code red?) – and I wanted a discussion that provided insights into how to manage this in a way that brought immediate results but also good long-term gain.</p>
<p class="MsoNormal">During this program, <a href="http://www.venafi.com/leadership.html">Paul</a> (from <a href="http://www.venafi.com/">Venafi</a>) and I start by exploring how to engage business users in the conversation. We progress to tactical and strategic ways to address this challenge while realizing this is an opportunity to make some improvements that bring better future results.</p>
<p class="MsoNormal">It comes from planning and following a process informed by experience – and we’ll share the insights with you in 30 minutes or less!</p>
<p class="MsoNormal">In the wrap-up, I suggest following the approach of plan-do-review, outlined in this podcast: <a href="http://www.securitycatalyst.com/blog/2008/01/31/the-security-catalyst-show-plan-do-review-your-way-to-success/">http://www.securitycatalyst.com/blog/2008/01/31/the-security-catalyst-show-plan-do-review-your-way-to-success/</a></p>
<p class="MsoNormal">Tune in next week for the debut of the Pop Culture Security podcast – your monthly “how-to” for Security Awareness Training.</p>
<p><!--EndFragment-->
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Ftsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Ftsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/tsc-may-21-2008-the-right-way-to-address-the-debian-openssl-vulnerability/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Introduction a brave new program &#8211; Driving the Digital Revolution</title>
		<link>http://www.securitycatalyst.com/introduction-a-brave-new-program-driving-the-digital-revolution/</link>
		<comments>http://www.securitycatalyst.com/introduction-a-brave-new-program-driving-the-digital-revolution/#comments</comments>
		<pubDate>Wed, 13 Feb 2008 22:28:19 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[cornell]]></category>
		<category><![CDATA[driving the digital revolution]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/2008/02/13/introduction-a-brave-new-program-driving-the-digital-revolution/</guid>
		<description><![CDATA[I am excited to introduce to you a new program that I host and produce for Cornell University called “Driving the Digital Revolution.” Driving the Digital Revolution is a simple, but powerful, way to consider the changes taking place around us every day. The digital revolution has led cultures from poverty, literally changed the face [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fintroduction-a-brave-new-program-driving-the-digital-revolution%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fintroduction-a-brave-new-program-driving-the-digital-revolution%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I am excited to introduce to you a new program that I host and produce for <a href="http://www.cis.cornell.edu/" target="_blank">Cornell University</a> called “<a href="http://www.cis.cornell.edu/alumniblog/" target="_blank"><em>Driving the Digital Revolution.</em></a>”</p>
<p>Driving the Digital Revolution is a simple, but powerful, way to consider the changes taking place around us every day. The digital revolution has led cultures from poverty, literally changed the face of global business, local business and even impacted on the family structure. Without question, the digital revolution both counts on and plays an active role in shaping how people protect information.</p>
<p>Cornell takes its role in driving the digital revolution seriously. In both education and research, emphasis is placed not only on the field of study, but in how that subject is being transformed by advances in computing and information resources. It realizes that as ideas and technologies are advanced, we have an obligation to not only consider the consequences, but to study and anticipate the unintended consequences.</p>
<p>I am sharing this with you for two reasons:</p>
<p>(1) I am passionate about this series and the opportunity to work with other experts to dig deeper and uncover important concepts that are driving the digital revolution; their words have a lasting impact on me, and I believe they will on you, too.</p>
<p>(2) We are at a place in our industry when we need change. We need to grab on to a vision of hope and drive change. Studying how Cornell participates in driving the digital revolution is a blueprint for our success.</p>
<p>So sit back, plug in and consider the words &#8212; and passion &#8212; of Dean Constable and how they apply to what you do. Working together, we can change the way people protect information.</p>
<p><strong>There are three ways to listen and subscribe (so you get every episode)</strong><br />
1. Each episode incorporates the ability to listen on the website! Simply point your browser to http://www.cis.cornell.edu/alumniblog/ and press play<br />
2. You can download this episode directly: http://www.cis.cornell.edu/alumniblog/podcast/cornell-ddr-01.mp3<br />
3. If you prefer to use and subscribe using RSS, here is the feed: http://www.cis.cornell.edu/alumniblog/feed/
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fintroduction-a-brave-new-program-driving-the-digital-revolution%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fintroduction-a-brave-new-program-driving-the-digital-revolution%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/introduction-a-brave-new-program-driving-the-digital-revolution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.cis.cornell.edu/alumniblog/podcast/cornell-ddr-01.mp3" length="29072811" type="audio/mpeg" />
			<itunes:keywords>catalyst,cornell,driving the digital revolution,Podcast</itunes:keywords>
		<itunes:subtitle>I am excited to introduce to you a new program that I host and produce for Cornell University called âDriving the Digital Revolution.â  Driving the Digital Revolution is a simple, but powerful, way to consider the changes taking place around us eve...</itunes:subtitle>
		<itunes:summary>I am excited to introduce to you a new program that I host and produce for Cornell University called âDriving the Digital Revolution.â

Driving the Digital Revolution is a simple, but powerful, way to consider the changes taking place around us every day. The digital revolution has led cultures from poverty, literally changed the face of global business, local business and even impacted on the family structure. Without question, the digital revolution both counts on and plays an active role in shaping how people protect information.

Cornell takes its role in driving the digital revolution seriously. In both education and research, emphasis is placed not only on the field of study, but in how that subject is being transformed by advances in computing and information resources. It realizes that as ideas and technologies are advanced, we have an obligation to not only consider the consequences, but to study and anticipate the unintended consequences.

I am sharing this with you for two reasons:

(1) I am passionate about this series and the opportunity to work with other experts to dig deeper and uncover important concepts that are driving the digital revolution; their words have a lasting impact on me, and I believe they will on you, too.

(2) We are at a place in our industry when we need change. We need to grab on to a vision of hope and drive change. Studying how Cornell participates in driving the digital revolution is a blueprint for our success.

So sit back, plug in and consider the words -- and passion -- of Dean Constable and how they apply to what you do. Working together, we can change the way people protect information.

There are three ways to listen and subscribe (so you get every episode)
1. Each episode incorporates the ability to listen on the website! Simply point your browser to http://www.cis.cornell.edu/alumniblog/ and press play
2. You can download this episode directly: http://www.cis.cornell.edu/alumniblog/podcast/cornell-ddr-01.mp3
3. If you prefer to use and subscribe using RSS, here is the feed: http://www.cis.cornell.edu/alumniblog/feed/</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>The Security Catalyst Show &#124; Plan &#8211; Do &#8211; Review your way to success</title>
		<link>http://www.securitycatalyst.com/the-security-catalyst-show-plan-do-review-your-way-to-success/</link>
		<comments>http://www.securitycatalyst.com/the-security-catalyst-show-plan-do-review-your-way-to-success/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 05:56:10 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[high/scope]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/2008/01/31/the-security-catalyst-show-plan-do-review-your-way-to-success/</guid>
		<description><![CDATA[Into the Breach is really taking shape &#8211; but I have been eager to get back behind the microphone and share the ideas and concepts I have been working on. You witnessed my transition to The Security Catalyst last year, and with it, my focus on changing the way people protect information. In this podcast, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-show-plan-do-review-your-way-to-success%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-show-plan-do-review-your-way-to-success%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.intothebreach.com/" target="_blank">Into the Breach</a> is really taking shape &#8211; but I have been eager to get back behind the microphone and share the ideas and concepts I have been working on. You witnessed my transition to The Security Catalyst last year, and with it, my focus on changing the way people protect information.</p>
<p>In this podcast, I share a simple and powerful concept that can be applied to anything you do: PLAN &#8211; DO &#8211; REVIEW</p>
<p>I first learned about PLAN &#8211; DO &#8211; REVIEW a few years back when it was time to learn about nursery schools, and one of the schools followed the HIGH/SCOPE method. Curious, I went to explore and learn more. Since then, I have tested and adapted the approach for my own use &#8211; with excellent results.</p>
<p>Now I share my experience with you.</p>
<p>Here are three links if you would like to learn more:</p>
<p>http://www.highscope.org/</p>
<p>http://en.wikipedia.org/wiki/High/Scope</p>
<p>http://www.perpetualpreschool.com/highscope/highscope_info.htm</p>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-show-plan-do-review-your-way-to-success%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-show-plan-do-review-your-way-to-success%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/the-security-catalyst-show-plan-do-review-your-way-to-success/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Security Catalyst Podcast: A Conversation with Brian Chess</title>
		<link>http://www.securitycatalyst.com/the-security-catalyst-podcast-a-conversation-with-brian-chess/</link>
		<comments>http://www.securitycatalyst.com/the-security-catalyst-podcast-a-conversation-with-brian-chess/#comments</comments>
		<pubDate>Thu, 29 Nov 2007 00:18:15 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[application security]]></category>
		<category><![CDATA[brian chess]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/2007/11/28/the-security-catalyst-podcast-a-conversation-with-brian-chess/</guid>
		<description><![CDATA[On this program, we share a conversation with Brian Chess, the author of Secure Programming with Static Analysis &#8211; a conversation that is a must listen for business leaders, security professionals and developers if you want to learn how to engage your teams to better protect information. Brian takes an approach with secure programming that [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-podcast-a-conversation-with-brian-chess%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-podcast-a-conversation-with-brian-chess%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>On this program, we share a conversation with Brian Chess, the author of <a href="http://www.amazon.com/Programming-Analysis-Addison-Wesley-Software-Security/dp/0321424778/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1196292147&amp;sr=8-1" target="_blank">Secure Programming with Static Analysis</a> &#8211; a conversation that is a must listen for business leaders, security professionals and developers if you want to learn how to engage your teams to better protect information.</p>
<p>Brian takes an approach with secure programming that is similar to the approach I follow when assessing and implementing awareness and training programs. So whether you are a developer or not, you will change the way you protect information by listening to Brian!</p>
<p><strong>What I took away from my conversation with Brian</strong><br />
After reflecting on our conversation (I explain more during the podcast), here are the top five points I took away:</p>
<p>1. Introspection is important when looking to protect information. To me, this also means we have to stop blaming and looking to assign blame. We can look within, take (and encourage) responsibility and find solutions.</p>
<p>2. Trust is paramount.  We have to find ways to establish and maintain trust, offline and online.</p>
<p>3. We need to develop processes and tools to support our experts in a way that naturally engages them and encourages their participation in information protection.</p>
<p>4. New processes, new learning and new tools require an initial investment (time, money and resources) that may sometimes seem sizeable – but the savings are realized rapidly and bring long-term positive benefits.</p>
<p>5. In security, we need to stop griping and learn to be good coming from behind. It&#8217;s okay, and we can do it.</p>
<p>What did you take away from this conversation? Send me an email: s&#101;&#99;&#117;rity&#99;at&#97;&#108;&#121;&#115;t&#64;&#103;&#109;ail&#46;&#99;o&#109;, or better yet &#8211; join us in the security catalyst community – <a href="http://www.securitycatalyst.org" target="_blank">www.securitycatalyst.org</a> and share your insights with others.</p>
<p><strong>Information and Links</strong></p>
<p>Brian Chess, Ph.D., Founder &amp; Chief Scientist<a href="http://extra.fortifysoftware.com/blog/bloggers.html" target="_blank"><br />
http://extra.fortifysoftware.com/blog/bloggers.html </a></p>
<p>Dr. Chess’s research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedger.</p>
<p>Secure Programming with Static Analysis<a href="http://www.amazon.com/Programming-Analysis-Addison-Wesley-Software-Security/dp/0321424778/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1196292147&amp;sr=8-1" target="_blank"></p>
<p>http://www.amazon.com/Programming-Analysis-Addison-Wesley-Software-Security/dp/0321424778/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1196292147&amp;sr=8-1</a></p>
<p>Blogging with Brian Chess<a href="http://extra.fortifysoftware.com/blog/" target="_blank"></p>
<p>http://extra.fortifysoftware.com/blog/</a></p>
<p><strong>Serving Your Needs</strong><br />
I thoroughly enjoy researching and producing these podcasts – and looking forward to getting back into a programming schedule with a bit more regularity. I’ve also been impressed with the Talk Shoe service, and considering hosting more podcasts through Talk Shoe so you can listen in live.</p>
<p>Let me know if you would listen live and participate if we made that an option, and who you would like to share a conversation with by sending me a note: &#115;&#101;cu&#114;it&#121;&#99;a&#116;&#97;&#108;&#121;&#115;t&#64;&#103;&#109;&#97;i&#108;.c&#111;mAs always, thanks for the gift you give me by listening. If you liked the program, tell a friend. If not, tell me!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-podcast-a-conversation-with-brian-chess%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-podcast-a-conversation-with-brian-chess%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/the-security-catalyst-podcast-a-conversation-with-brian-chess/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Security Catalyst Podcast – Why Virtual Teams Fail (and how to avoid it)</title>
		<link>http://www.securitycatalyst.com/the-security-catalyst-podcast-%e2%80%93-why-virtual-teams-fail-and-how-to-avoid-it/</link>
		<comments>http://www.securitycatalyst.com/the-security-catalyst-podcast-%e2%80%93-why-virtual-teams-fail-and-how-to-avoid-it/#comments</comments>
		<pubDate>Sat, 03 Nov 2007 11:19:06 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Podcast]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[online collaboration]]></category>
		<category><![CDATA[virtual teams]]></category>
		<category><![CDATA[web working]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/2007/11/03/the-security-catalyst-podcast-%e2%80%93-why-virtual-teams-fail-and-how-to-avoid-it/</guid>
		<description><![CDATA[This podcast explores how and why virtual teams fail, based on new research from a group of graduate students at Johns Hopkins Carey School of Business. My belief is that in order to protect information, we have to support the individual – and make it easier for them to do their job. By learning more [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-podcast-%25e2%2580%2593-why-virtual-teams-fail-and-how-to-avoid-it%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-podcast-%25e2%2580%2593-why-virtual-teams-fail-and-how-to-avoid-it%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>This podcast explores how and why virtual teams fail, based on new research from a group of graduate students at Johns Hopkins Carey School of Business.</p>
<p>My belief is that in order to protect information, we have to support the individual – and make it easier for them to do their job. By learning more about how virtual teams fail, we can learn how to avoid mistakes and build stronger and more effective collaboration opportunities – where people can do their jobs while taking responsibility for protecting information. By absorbing this research, you may also learn how to work more effectively on your own virtual teams.</p>
<p>After our interview, I share the top five things that I learned about nurturing and protecting virtual teams. I invite you to sit back, listen, learn and contribute. I’m happy to keep the conversation going in the <a href="http://www.securitycatalyst.org/forums/index.php" target="_blank">security catalyst community</a>.</p>
<p><strong>Background: Bring new knowledge to the field of work team behavior</strong><br />
A group of five graduate students (<em>Robert Darling, Cari Endicott, Lisa Fratino, Matsuno Inoue, and Ellen Snydman</em>) from the <a href="http://carey.jhu.edu/" target="_blank">Carey Business School of Johns Hopkins University</a> participating in a team building course under the leadership of Dr. Robert Pernick were charged with bringing new knowledge to the field of teaming.</p>
<p>This group elected to research the world of virtual teaming, and in doing so, found that here is a great body of literature on what makes virtual teams successful, but little written about what causes them to fail or become sub-optimized.  The team’s first research effort was to conduct structured interviews with a group of virtual teaming experts.</p>
<p>The experts interviews generally agreed that the success of virtual teams were threatened by:<br />
•    Concerns regarding the ability to protect sensitive information<br />
•    Lack of a single platform that provides all the tools necessary to optimize<br />
•    The struggles of virtual communication<br />
•    Poorly or under-trained users<br />
•    The challenge of building trust  without the use of face-to-face communication</p>
<p>Overall, the experts agreed that all of these obstacles can be overcome and unless combined into the “perfect storm” are not likely to cause catastrophic failure. The experts felt very good about the work that is be done virtually and believe that the use of virtual teams will become even more prevalent into today’s global society.</p>
<p>The second phase of research involved the distribution of a short, online survey about virtual work.  The results of the survey are still be collected, but at this point there seems to be a great deal of overlap with the findings from the subject matter experts.  The podcast you are listening to will explore both elements of the research and will introduce yet another subject matter expert, Stu Snydman, the <a href="http://library.stanford.edu/depts/dlss/" target="_blank">Manager of Digital Production at the Stanford University Libraries</a>.</p>
<p>This podcast was created and hosted by Michael Santarcangelo and expertly engineered by Steve Witt. Thank, Steve!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-podcast-%25e2%2580%2593-why-virtual-teams-fail-and-how-to-avoid-it%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-security-catalyst-podcast-%25e2%2580%2593-why-virtual-teams-fail-and-how-to-avoid-it%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/the-security-catalyst-podcast-%e2%80%93-why-virtual-teams-fail-and-how-to-avoid-it/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Catalyst Podcast &#8211; The Value of Fundamentals</title>
		<link>http://www.securitycatalyst.com/security-catalyst-podcast-the-value-of-fundamentals/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-podcast-the-value-of-fundamentals/#comments</comments>
		<pubDate>Tue, 17 Jul 2007 05:04:18 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/2007/07/17/security-catalyst-podcast-the-value-of-fundamentals/</guid>
		<description><![CDATA[I&#8217;m back, baby! I know I&#8217;ve been remiss in sharing some ideas and observations &#8211; but I&#8217;ve been really focused. As I continue to focus on changing how people protect information, I have come to appreciate the value of the fundamentals. I share some insights in this long overdue podcast.  Things you will learn by listening [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-podcast-the-value-of-fundamentals%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-podcast-the-value-of-fundamentals%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I&#8217;m back, baby! I know I&#8217;ve been remiss in sharing some ideas and observations &#8211; but I&#8217;ve been really focused. As I continue to focus on changing how people protect information, I have come to appreciate the value of the fundamentals. I share some insights in this <span class="Apple-style-span" style="text-decoration: line-through">long overdue</span> podcast.  Things you will learn by listening to this podcast:
<ul id="null">
<li>I am a yankees fan</li>
<li>Three lessons I took away from watching professionals and legends</li>
<li>How to have more fun at work</li>
</ul>
<p>I also share some updates on the Information Protection Assessment Toolkit, make a special offer and update some of my travel plans.  It&#8217;s nice to be back. We have an SRT coming up, and I have a lot I hope to share&#8230; more to come&#8230;  If you enjoy this, let me know. If not, let me know how I can make your job easier and improve the quality of your podcast experience. 
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-podcast-the-value-of-fundamentals%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-podcast-the-value-of-fundamentals%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-podcast-the-value-of-fundamentals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst: Family Security Series Podcast, Episode 2 – Using a Non-Administrative User</title>
		<link>http://www.securitycatalyst.com/security-catalyst-family-security-series-podcast-episode-2-%e2%80%93-using-a-non-administrative-user/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-family-security-series-podcast-episode-2-%e2%80%93-using-a-non-administrative-user/#comments</comments>
		<pubDate>Fri, 06 Apr 2007 03:43:43 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=319</guid>
		<description><![CDATA[You are invited to learn how to reduce the effectiveness of attacks and sleep better at night by using a non-administrative user account. In this brief podcast, we explain: -    why you should be using a non-administrative user account -    how to determine which type of account you are currently using -    how to create [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-family-security-series-podcast-episode-2-%25e2%2580%2593-using-a-non-administrative-user%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-family-security-series-podcast-episode-2-%25e2%2580%2593-using-a-non-administrative-user%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>You are invited to learn how to reduce the effectiveness of attacks and sleep better at night by using a non-administrative user account. In this brief podcast, we explain:<br />
-    why you should be using a non-administrative user account<br />
-    how to determine which type of account you are currently using<br />
-    how to create normal user accounts<br />
-    how to change to a regular user account</p>
<p>Thanks to a dedicated team of professionals, this podcast has been made better. If you see them on the street, give them a big hug. They worked hard (and continue to) to improve our efforts to make a difference:</p>
<blockquote><p>• Gary Morgan, CISSP<br />
• Alvin Liau, CISSP<br />
• George Viconovic, MCIW/D<br />
• James Costello, Security + SME<br />
• John Biasi<br />
• Peter Clark, CISSP</p></blockquote>
<p>If you have not yet joined the conversation in the Security Catalyst Community, please do so now: <a target="_blank" href="http://community.securitycatalyst.com/forums/index.php">http://community.securitycatalyst.com/forums/index.php<br />
</a><br />
The specific link for this discussion is here: <a target="_blank" href="http://community.securitycatalyst.com/forums/index.php/topic,335.0.html">http://community.securitycatalyst.com/forums/index.php/topic,335.0.html</a><br />
<em>(note: joining the community costs nothing – except your active participation!; we enforce a naming standard of using your full name. It helps us keep the supportive environment positive. We look forward to sharing ideas and learning with you.)<br />
</em></p>
<p><em><strong>Links and Information Mentioned During the Program</strong></em></p>
<p><strong>Least Privilege</strong></p>
<blockquote><p><em>In computer science and other fields the principle of minimal privilege, also known as the principle of least privilege or just least privilege, requires that in a particular abstraction layer of a computing environment every module (such as a process, a user or a program on the basis of the layer we are considering) must be able to access only such information and resources that are necessary to its legitimate purpose.</em><br />
<a target="_blank" href="http://en.wikipedia.org/wiki/Principle_of_least_privilege"><em>Source: Wikipedia: http://en.wikipedia.org/wiki/Principle_of_least_privilege</em></a></p></blockquote>
<p><strong>Determine the current status of a user account</strong></p>
<p>Two basic options in windows XP<br />
<em>Windows XP: Option 1</em><br />
• Start -> Run -> CMD (bring up a command prompt)<br />
• type ipconfig /renew (this will be in the show notes)<br />
• Limited Users will be given an error that access is denied.  Administrators will be allowed to renew their IP address.</p>
<p><em>Windows XP: Option 2</em><br />
• Start &#8211;> Control Panel<br />
• Launch the User Accounts application</p>
<p>If you are  a Limited User you will be presented with the option to Change your picture or to click on Mail or User Accounts.  • You are limited to changing your own password<br />
• changing your picture<br />
• or to set up your account to use a .NET Passport.</p>
<p>If you are an Administrator you will be given the option to Change an account, create a new account or change the way users log on or off.</p>
<p>For more ways, join the discussion in the catalyst community forums: <a target="_blank" href="http://community.securitycatalyst.com/forums/index.php/topic,335.0.html">http://community.securitycatalyst.com/forums/index.php/topic,335.0.html<br />
</a></p>
<p><em>Mac OSX</em><br />
• System Preferences &#8211;> Accounts<br />
• Right under the name it tells you the kind of account they have</p>
<p><strong>Create a non-admin account</strong></p>
<p><em>Mac OSX</em><br />
• System Preferences &#8211;> Accounts<br />
• Check that the lock is unlocked; if not, click it and enter your password<br />
• click on the + sign<br />
• Enter in the information, including a password<br />
• DO NOT check (make sure you leave blank) the box for &#8216;Allow user to administer this computer&#8217;</p>
<p><em>Windows, pre-vista</em><br />
• Start -> control panel<br />
• Select &#8216;User Accounts&#8217;<br />
• Select &#8216;Create a new account&#8217;<br />
• Type in the name of the new user account<br />
• Select the &#8216;Next >&#8217; button<br />
• Select the &#8216;Limited&#8217; radio button<br />
• select the &#8216;Create Account&#8217; button</p>
<p>you&#8217;re not done! Time to select a good password<br />
(We will go into details on good passwords in the future)<br />
• You will be presented with a &#8216;User Accounts&#8217; screen, with a &#8216;Pick a task&#8217; option.  Select &#8216;Change an account&#8217; option<br />
• Select the account you just created<br />
• On the next screen &#8216;What do you want to change about Child 1&#8242;s account?&#8217; select &#8216;Create a password&#8217;<br />
• Then enter a strong password, in the first two boxes, enter a password hint in the Third box.  Then press the &#8216;Create Password&#8217; button&#8217;</p>
<p><em>Support the efforts of The Traveling Catalyst!</em><br />
<strong>RV Tour (our pre-tour warmup for the Security Revival Tour)<br />
</strong><br />
• Nashville (April 24 – 25)<br />
• Atlanta (April 26 – May 3 or 4)<br />
• Key West (May 3 or 4 until May <img src='http://www.securitycatalyst.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> • Baltimore/Washington/Northern Virginia (May 10 – May 18)</p>
<p>We’re working now to set up some public sessions of<br />
• Are You Making a Living or a Life?<br />
• Career Compass Coaching<br />
• Speaking About Security</p>
<p>We’re also interested in offering some public keynotes in each of the areas to support the efforts of security professionals. Send me an email if you’re interested (securit&#121;c&#97;t&#97;&#108;&#121;&#115;t&#64;&#103;&#109;&#97;&#105;l&#46;c&#111;m)</p>
<p>We are in the process of selecting cities for our &#8221;security revival tour&#8221; for the second half of 2007. If you would like us to bring our training to your city, send me an email: &#115;ec&#117;r&#105;t&#121;&#99;&#97;ta&#108;&#121;st&#64;gm&#97;il.&#99;om</p>
<p>Thanks for listening &#8211; now go make your user account changes and be safe out there!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-family-security-series-podcast-episode-2-%25e2%2580%2593-using-a-non-administrative-user%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-family-security-series-podcast-episode-2-%25e2%2580%2593-using-a-non-administrative-user%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-family-security-series-podcast-episode-2-%e2%80%93-using-a-non-administrative-user/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Episode 1 (of 7) &#8211; (Teach Your) Family Security Series Security Podcast &#8211; Operating System and Application Updates</title>
		<link>http://www.securitycatalyst.com/episode-1-of-7-teach-your-family-security-series-security-podcast-operating-system-and-application-updates/</link>
		<comments>http://www.securitycatalyst.com/episode-1-of-7-teach-your-family-security-series-security-podcast-operating-system-and-application-updates/#comments</comments>
		<pubDate>Fri, 02 Mar 2007 21:38:05 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=283</guid>
		<description><![CDATA[I feel like we&#8217;ve been building to this for a while now&#8230; Here is the first episode of the Family Security Series podcast. This episode focuses on operating system and application patching. The goal is to explain the basic approach, some configurations and then provide links and details, as available. I invite you to not [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fepisode-1-of-7-teach-your-family-security-series-security-podcast-operating-system-and-application-updates%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fepisode-1-of-7-teach-your-family-security-series-security-podcast-operating-system-and-application-updates%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I feel like we&#8217;ve been building to this for a while now&#8230; Here is the first episode of the Family Security Series podcast.  This episode focuses on operating system and application patching. The goal is to explain the basic approach, some configurations and then provide links and details, as available. I invite you to not only listen, but to share this podcast with others &#8211; especially those that you think would benefit from it.</p>
<p>We have also decided to include at least monthly programming designed to help consumers; this helps you with your awareness efforts.</p>
<p>I want to thank the advisory committee for their help. This episode is better because of:<br />
- <a href="http://www.andrewhay.ca">Andrew Hay</a>  | <a href="http://www.koteas.com">Founder and CEO of Koteas Corporation</a><br />
- <a href="http://www.remora.ca">Peter Clark</a><br />
- Alvin Liau, CISSP<br />
- <a href="http://www.john-biasi.com">John Biasi</a></p>
<p><strong>Basic Overview Sites (some of this material will be covered in future episodes)</strong><br />
<a href="http://www.microsoft.com/athome/security/default.mspx">Microsoft Security Site for Home Users</a><br />
<a href="http://www.apple.com/support/security/">Apple Security Site</a> (good starting point)<a href="http://www.apple.com/support/security/"> </a></p>
<p><strong>Links for Microsoft (Operating System)<br />
</strong><a href="http://update.microsoft.com/">Windows Update</a></p>
<p>If you need/want an alternative: <a href="http://www.autopatcher.com/whatsautopatcher/">AutoPatcher</a></p>
<p><strong>Links for Apple/Mac (Operating System)<br />
</strong><a href="http://docs.info.apple.com/article.html?artnum=106704">Mac OS X: Updating your software</a><br />
<strong>Application Update Links<br />
</strong><br />
<strong>For Microsoft Applications:</strong><br />
<a href="http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/systemrestore.mspx">Use System Restore to Undo Changes if Problems Occur</a><br />
<a href="http://office.microsoft.com/en-us/downloads/default.aspx">Product updates, free trials, and third-party downloads</a> (there is a button on the right hand side to allow you to check for updates)</p>
<p><strong>Other Updates we mentioned:</strong></p>
<p><a href="http://www.adobe.com/products/acrobat/readstep2.html">Download the latest version of Adobe Reader</a><br />
<a href="http://www.mozilla.com/en-US/firefox/">Firefox (browser)</a><br />
<a href="http://www.mozilla.com/en-US/thunderbird/">Thunderbird (email client)</a><br />
<a href="http://www.real.com/player">Real Player</a></p>
<p>(if you have others &#8211; send them to me at <a href="m&#97;&#105;l&#116;o:&#115;&#101;&#99;u&#114;&#105;ty&#99;at&#97;l&#121;&#115;&#116;&#64;g&#109;&#97;il&#46;&#99;&#111;m">s&#101;curit&#121;catal&#121;s&#116;&#64;&#103;&#109;&#97;&#105;&#108;&#46;c&#111;m</a> and I will include them in our <a href="http://www.securitycatalyst.com/familysecurityresources/">Family Security Resources Section</a>)</p>
<p><strong>Episode Lineup:</strong><br />
Episode 1: OS and Application Patching<br />
Episode 2: non-admin user<br />
Episode 3: Anti-Virus, Anti-Spyware and other needed protections<br />
Episode 4: Firewalls<br />
Episode 5: Backup<br />
Episode 6: Wireless Securiy Basics<br />
Episode 7: Professionals Best Practices</p>
<p>Come discuss this and other ways to help protect information in the <a href="http://community.securitycatalyst.com/forums/index.php">Security Catalyst Community</a>.</p>
<p>If this helped you, please invite two friends to listen.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fepisode-1-of-7-teach-your-family-security-series-security-podcast-operating-system-and-application-updates%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fepisode-1-of-7-teach-your-family-security-series-security-podcast-operating-system-and-application-updates%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/episode-1-of-7-teach-your-family-security-series-security-podcast-operating-system-and-application-updates/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Our first Security Podcast Q&amp;A with Adam Dodge</title>
		<link>http://www.securitycatalyst.com/our-first-security-podcast-qa-with-adam-dodge/</link>
		<comments>http://www.securitycatalyst.com/our-first-security-podcast-qa-with-adam-dodge/#comments</comments>
		<pubDate>Mon, 19 Feb 2007 19:17:07 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=263</guid>
		<description><![CDATA[Welcome to a new programming aspect of the Security Catalyst experience: our Q&#038;A podcast. After recording this weekend, we made the decision to run this today and push the Family Security Series back a few days (the team engaged in advising me has really brought on a lot of value and I am looking forward [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Four-first-security-podcast-qa-with-adam-dodge%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Four-first-security-podcast-qa-with-adam-dodge%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Welcome to a new programming aspect of the Security Catalyst experience: our Q&#038;A podcast. After recording this weekend, we made the decision to run this today and push the Family Security Series back a few days (the team engaged in advising me has really brought on a lot of value  and I am looking forward to getting that program started).</p>
<p><strong>So, what can you expect from this program?</strong><br />
- Our goal is to review questions and answer them monthly<br />
- We will answer questions sent in by readers and listeners, across three basic types:</p>
<blockquote><p>- career<br />
- consumer<br />
- business</p></blockquote>
<p>- Depending on each show, we may not cover each segment (or we might be covering one topic across all three). We’ll see how it goes.<br />
- We are also taking the time for each program to research the questions a bit, and then are combining our experience, opinions and research to provide what we hope to be useful and helpful information.<br />
- Each show will list links (which you’ll see below).</p>
<p><strong>Here is our disclaimer<br />
</strong>This is our best effort. To really benefit from this experience, we invite you to get engaged in the process:<br />
- if you see something we missed, join us in the discussion forum and chime in<br />
- use our experience as a guide for your own decision making<br />
- if you need more help, join the security catalyst community (note the naming convention of: Firstname.Lastname)</p>
<p><strong>On this Episode (three questions)<br />
</strong><br />
<strong>1. &#8220;I was curious if you are aware of any resources for security study and job-seeking, as I&#8217;m entirely self-taught. At this point I scan the logs and read whatever I can on the web and industry rags. I do Windows but prefer linux for its stability &#8211; most of my tools are on the linux box. Pisses off my boss to no end <img src='http://www.securitycatalyst.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Not bad for self-taught, but it&#8217;s time for a large pay raise&#8221;  &#8211; Jeff</strong></p>
<p>Links from our answer:<br />
NSA as Centers of Academic Excellence in Information Assurance Education (CAEIAE) <a target="_blank" href="http://www.nsa.gov/ia/academia/caeiae.cfm">http://www.nsa.gov/ia/academia/caeiae.cfm</a><br />
<a target="_blank" href="http://www.cnss.gov/full-index.html"> http://www.cnss.gov/full-index.html</a></p>
<p>A list of all CAEIAE insitutions and the areas they have certified in is available here <a target="_blank" href="http://www.nsa.gov/ia/academia/iacmap.cfm">http://www.nsa.gov/ia/academia/iacmap.cfm</a></p>
<p>CISA &#8211; <a target="_blank" href="http://www.securitycatalyst.com/www.isaca.org/cisa/">www.isaca.org/cisa/</a><br />
CISM &#8211; <a target="_blank" href="http://www.securitycatalyst.com/www.isaca.org/cism/">www.isaca.org/cism/</a><br />
CISSP &#8211; www.isc2.org/<br />
SANS – <a target="_blank" href="http://www.securitycatalyst.com/www.giac.org/certifications/roadmap.php">www.giac.org/certifications/roadmap.php</a><br />
Norwich &#8211; <a target="_blank" href="http://www.msia.norwich.edu/insecure/">http://www.msia.norwich.edu/insecure/</a></p>
<p>Join the discussion in the Security Catalyst Community:</p>
<p><a target="_blank" href="http://community.securitycatalyst.com/forums/index.php/topic,95.0.html">http://community.securitycatalyst.com/forums/index.php/topic,95.0.html</a><br />
and<br />
<a target="_blank" href="http://community.securitycatalyst.com/forums/index.php/topic,116.0.html"> http://community.securitycatalyst.com/forums/index.php/topic,116.0.html</a></p>
<p><strong>2. &#8220;I&#8217;m looking for some topic ideas relating to some awareness initiatives here where I work. I know you&#8217;ve been asking for feedback on topics, and I was wondering if you&#8217;d share any of your findings.&#8221; &#8211; Jim</strong></p>
<p><em>Special Offer: If you send me an email at <a target="_blank" href="m&#97;i&#108;&#116;&#111;:&#115;ec&#117;&#114;&#105;t&#121;cat&#97;&#108;ys&#116;&#64;g&#109;&#97;il.&#99;om?subject=Awareness Survey">s&#101;&#99;&#117;ritycat&#97;&#108;&#121;&#115;&#116;&#64;gma&#105;l&#46;c&#111;m</a> &#8211; I will work with you to survey your audience and provide the results to you to help you kick-start your awareness program. While I welcome the opportunity to explain some of our research, there are no strings attached. This is what I do for a living, and if it helps get our much needed awareness efforts kick-started, then I’ll contribute this to the industry.</em></p>
<p>Links:<br />
Come discuss this with us in the forum:<br />
<a target="_blank" href="http://community.securitycatalyst.com/forums/index.php/topic,41.0.html"> http://community.securitycatalyst.com/forums/index.php/topic,41.0.html</a></p>
<p>Some other ideas for topics:<br />
NIST 800-69, Guidance for Securing XP Home: <a target="_blank" href="http://csrc.nist.gov/itsec/guidance_WinXP_Home.html">http://csrc.nist.gov/itsec/guidance_WinXP_Home.html</a> (** this is what we are using for the first 5 episodes of the FSS Podcast)<br />
CERT Home User Security: <a target="_blank" href="http://www.cert.org/homeusers/HomeComputerSecurity/">http://www.cert.org/homeusers/HomeComputerSecurity/</a></p>
<p><strong>3. &#8220;I have been researching antivirus software for too long and just keep going in circles. I cannot distinguish between different antivirus software vendors because of either their marketing hype, inconsistent reviews, FUD, etc. Is there really a quantifibable difference or is it just opinions? What are your thoughts on this and could you provide an antivirus suggestion? At this moment I am leaning more towards either Zone Alarm Security Suite, or Kerio and NOD32.&#8221; &#8211; Eric<br />
</strong><br />
Links<br />
If you are looking for more information on how specific AV software did in testing, check out<br />
- AV Test (<a target="_blank" href="http://www.securitycatalyst.com/www.av-test.org">www.av-test.org</a>), independent testing lab in Germany<br />
- CheckVir (<a target="_blank" href="http://www.securitycatalyst.com/www.checkvir.com">www.checkvir.com</a>), independent testing lab in Hungary<br />
- ICSA Labs (<a target="_blank" href="http://www.securitycatalyst.com/www.icsalabs.com">www.icsalabs.com</a>), one of the first organizations to start testing the claims of AV vendors, now part of Cybertrust (<a target="_blank" href="http://www.securitycatalyst.com/www.cybertrust.com">www.cybertrust.com</a>)</p>
<p>For those adventurous types that are looking to run a few in house tests, here are some resources that might help<br />
- The European Expert Group for IT-Security (<a target="_blank" href="http://www.securitycatalyst.com/www.eicar.org">www.eicar.org</a>), Look for the &#8220;Anti-Malware Testfile&#8221; link on the main page</p>
<p>Free AV resources<br />
- AVG Free &#8211; <a target="_blank" href="http://free.grisoft.com/doc/1">http://free.grisoft.com/doc/1</a><br />
- Avira AntiVir Personal Edition &#8211; <a target="_blank" href="http://www.free-av.com/antivirus/allinonen.html">http://www.free-av.com/antivirus/allinonen.html</a><br />
- ClamWim &#8211; <a target="_blank" href="http://www.clamwin.com/">http://www.clamwin.com/</a><br />
- TrendMirco Free Online Virus Scanner &#8211; <a target="_blank" href="http://housecall.trendmicro.com/">http://housecall.trendmicro.com/</a></p>
<p>Subscription AV resources<br />
- CA eTurst Antivirus &#8211; <a target="_blank" href="http://www3.ca.com/solutions/Product.aspx?ID=156">http://www3.ca.com/solutions/Product.aspx?ID=156</a><br />
- Symantec (number of different products for home/small to mid business/enterprise) &#8211; <a target="_blank" href="http://www.symantec.com/index.htm">http://www.symantec.com/index.htm</a><br />
- McAfee (same as symantec, differen products for different sectors) &#8211; <a target="_blank" href="http://www.mcafee.com/us/">http://www.mcafee.com/us/</a><br />
- NOD32 &#8211; <a target="_blank" href="http://www.eset.com/">http://www.eset.com/</a><br />
- Sophos (for businesses) &#8211; <a target="_blank" href="http://www.sophos.com/">http://www.sophos.com/</a></p>
<p>Additional reviews<br />
- AV Test &#8211; <a target="_blank" href="http://www.av-test.org">http://www.av-test.org</a><br />
- CheckVir &#8211; <a target="_blank" href="http://www.checkvir.com">http://www.checkvir.com</a><br />
- ICSA Labs &#8211; <a target="_blank" href="http://www.icsalabs.com">http://www.icsalabs.com</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Four-first-security-podcast-qa-with-adam-dodge%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Four-first-security-podcast-qa-with-adam-dodge%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/our-first-security-podcast-qa-with-adam-dodge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst (Security Podcast) Update for February 8 2007</title>
		<link>http://www.securitycatalyst.com/security-catalyst-security-podcast-update-for-february-8-2007/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-security-podcast-update-for-february-8-2007/#comments</comments>
		<pubDate>Thu, 08 Feb 2007 19:18:56 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=251</guid>
		<description><![CDATA[I know, I know… all work and no play. I can tell when I’ve been away from podcasting for a few days (okay, weeks) when I start getting polite emails and nudges… well, here is a quick audio update for you. If you’ve been following this site for a while, you may recall that I [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-security-podcast-update-for-february-8-2007%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-security-podcast-update-for-february-8-2007%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I know, I know… all work and no play. I can tell when I’ve been away from podcasting for a few days (okay, weeks) when I start getting polite emails and nudges… well, here is a quick audio update for you.</p>
<p>If you’ve been following this site for a while, you may recall that I took some time at the turn of the year to think and plan how to be more effective in my business, as a blogger and as a podcaster. As a result of that planning (and my quest to regain some harmony in my life), we dedicated the entire month of January, and now some of February to documenting our approach, value and explaining our focus: to create, design and deliver exceptional experiences that help transform how organizations think about and protect information.</p>
<p>As a result, I am excited. I am healthy. And I am ready to get back behind the mic. Of course, I need to make sure that we keep my team healthy, active and busy… but as that is coming more clearly into focus, I’ll have more time to get back to active podcasting.</p>
<p>In this update:<br />
The 5 Steps to protecting your computer<br />
Here are the five basic steps that anyone with a computer should be following<br />
1. Update your operating system and applications<br />
2. Use a non-admin account for general use<br />
3. Install, configure and use anti-virus, anti-spyware and other malware protections<br />
4. Install, configure and use a firewall<br />
5. Backup, backup, backup</p>
<p>Each of the next five episodes will cover each of those steps, exploring the how and why in a way that we can share with technical and non-technical people alike. Then we’ll produce two additional programs to cover basic wireless configuration and some additional tips from the pros.</p>
<p><strong>Our Awareness Experiences and Efforts</strong><br />
In this update, I briefly mentioned that I am focusing on providing two exceptional experiences and a new way to handle security awareness</p>
<p>Speaking about Security<br />
<em>This two-day intensive experience is designed to explore the power of the narrative and teach professionals how to communicate about security concepts more effectively. Currently available as private classes; we are looking into holding some public courses.</em></p>
<p>Avoiding the Breach<br />
<em>Based on the research and prescription for success from my upcoming book, this two-day experience is an entertaining and proven approach to transforming how technical and non-technical people in your organization think about and protect information. Currently available as private classes; we are looking into holding some public courses.</em></p>
<p>Security Awareness Transformation<br />
<em>This is an exciting offering where we are combining the power of social media with our proven ability to connect with users with strategies to better protect themselves and their information (as well as yours).</em></p>
<p>For each of these, I will be sharing key concepts, lessons and strategies over the coming year. I’m interested in taking an approach of sharing the information so we all benefit, and then working with companies that are interested in being supported through their transformation. If you want some information in the meantime, shoot me an email. I&#8217;m excited about these areas and always interested to share some energy, passion and insight.</p>
<blockquote><p><em>I’m currently looking for five (5) companies to work with me on each of these experiences to help validate some changes and approaches. If you are interested, please contact me and we can talk about some incentives I am currently offering to those interested in making an impact in 2007 &#8211; secu&#114;&#105;&#116;yca&#116;&#97;&#108;&#121;&#115;&#116;&#64;&#103;&#109;a&#105;&#108;.c&#111;&#109;</em></p></blockquote>
<p><strong>My approach to podcasting for 2007<br />
</strong>We will share our research, knowledge, insights and work to provide you with insights, information, facts and templates to be more effective. I’ve also already announced some new programming we’re starting this year… but don’t worry, I’ll continue, when possible, to release some shorter podcasts that capture my thinking, my passion and help to get it out.</p>
<p>If you want to help: se&#99;&#117;r&#105;tycat&#97;&#108;&#121;&#115;&#116;&#64;&#103;m&#97;&#105;l.&#99;&#111;m</p>
<p>More to come soon…
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-security-podcast-update-for-february-8-2007%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-security-podcast-update-for-february-8-2007%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-security-podcast-update-for-february-8-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst Podcast &#8211; Preparing for Daylight Savings Time Changes in 2007</title>
		<link>http://www.securitycatalyst.com/security-catalyst-podcast-preparing-for-daylight-savings-time-changes-in-2007/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-podcast-preparing-for-daylight-savings-time-changes-in-2007/#comments</comments>
		<pubDate>Fri, 19 Jan 2007 07:06:10 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=234</guid>
		<description><![CDATA[Did you know about the changes in Daylight Savings Time for 2007? Have you already assessed the plan you and your company will use to reduce friction? For the first Security Catalyst podcast of 2007, I decided to push the (Teach Your) Family Security Series back a week in order to shed some light on [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-podcast-preparing-for-daylight-savings-time-changes-in-2007%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-podcast-preparing-for-daylight-savings-time-changes-in-2007%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Did you know about the changes in Daylight Savings Time for 2007? Have you already assessed the plan you and your company will use to reduce friction? For the first Security Catalyst podcast of 2007, I decided to push the (Teach Your) Family Security Series back a week in order to shed some light on the changes that the shift in Daylight Savings Time (DST) will see in 2007.</p>
<p>During this episode, we explore:<br />
The improvements planned for 2007, which include<br />
* More programming and a focus on series (Family Security, Hard Drive Encryption, etc.)<br />
* The change to a more consultative approach &#8212; so you can work smarter, not harder<br />
* The introduction of the monthly <em><strong>Security Q&#038;A with Adam Dodge</strong></em><br />
* The introduction of the monthly <em><strong>Privacy Stratgies with John Sileo</strong></em><br />
* The launch of the Catalyst Community Forums <a target="_blank" href="http://community.securitycatalyst.com/forums/index.php">http://community.securitycatalyst.com/forums/index.php</a></p>
<blockquote><p><em><strong>Note: please come and join us in the forums, but please register using the convention firstname.lastname and include your full name in your signature. Thanks!</strong></em></p></blockquote>
<p><strong>Daylight Savings Time 2007</strong></p>
<p>Now takes effect three weeks earlier, on Sunday March 11, 2007<br />
Ends one week later, Sunday November 4, 2007</p>
<p>Some useful links to help you get started in your preparation. <em>More will be maintained in the Catalyst Community Forum Topic (along with my outline for a basic action plan):<br />
</em><br />
Community Forum Topic: <a target="_blank" href="http://community.securitycatalyst.com/forums/index.php/topic,32.0.html">http://community.securitycatalyst.com/forums/index.php/topic,32.0.html</a></p>
<p>Our initial heads up:<br />
<a target="_blank" href="http://www.securitycatalyst.com/2006/12/04/dst2007-%e2%80%93-springing-ahead-of-time/">http://www.securitycatalyst.com/2006/12/04/dst2007-%e2%80%93-springing-ahead-of-time/</a> (hat tip to Ron Woerner for being ahead of the curve)</p>
<p>The CISCO briefings on the events in Oz:</p>
<p>Daylight Savings Time Impact on Cisco Security MARS in Australia<br />
<a target="_blank" href="http://www.cisco.com/en/US/products/ps6241/products_tech_note09186a0080626184.shtml">http://www.cisco.com/en/US/products/ps6241/products_tech_note09186a0080626184.shtml</a></p>
<p>Australian 2006 Daylight Saving Impact on Data Center/GSS and Branch Office Application Products<br />
<a target="_blank" href="http://www.cisco.com/en/US/products/hw/contnetw/ps4162/products_tech_note09186a0080626ac6.shtml">http://www.cisco.com/en/US/products/hw/contnetw/ps4162/products_tech_note09186a0080626ac6.shtml</a></p>
<p>Vendors (start your search here):<br />
Microsoft: <a target="_blank" href="http://www.microsoft.com/windows/timezone/dst2007.mspx">http://www.microsoft.com/windows/timezone/dst2007.mspx</a></p>
<p>Cisco: <a target="_blank" href="http://www.cisco.com/en/US/products/sw/custcosw/ps1973/products_field_notice09186a008076fca2.shtml">http://www.cisco.com/en/US/products/sw/custcosw/ps1973/products_field_notice09186a008076fca2.shtml<br />
</a></p>
<p>SUN (Java Runtime Environment): <a target="_blank" href="http://java.sun.com/developer/technicalArticles/Intl/USDST_Faq.html">http://java.sun.com/developer/technicalArticles/Intl/USDST_Faq.html</a></p>
<p>Oracle: <a target="_blank" href="http://blogs.oracle.com/schan/2006/12/26">http://blogs.oracle.com/schan/2006/12/26</a></p>
<p>IBM:<br />
<a target="_blank" href="http://www-1.ibm.com/support/docview.wss?rs=2004&#038;context=SSVHZU&#038;dc=D600&#038;uid=swg21248273&#038;loc=en_US&#038;cs=UTF-8&#038;lang=en">http://www-1.ibm.com/support/docview.wss?rs=2004&#038;context=SSVHZU&#038;dc=D600&#038;uid=swg21248273&#038;loc=en_US&#038;cs=UTF-8&#038;lang=en</a></p>
<p>If you liked this program, please take a moment to subscribe and invite two friends to subscribe, too. We can all make 2007 a year where we think about and practice security more effectively!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-podcast-preparing-for-daylight-savings-time-changes-in-2007%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-podcast-preparing-for-daylight-savings-time-changes-in-2007%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-podcast-preparing-for-daylight-savings-time-changes-in-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst &#8211; December 31, 2006 &#8211; In-depth with Punch Scan</title>
		<link>http://www.securitycatalyst.com/security-catalyst-december-31-2006-in-depth-with-punch-scan/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-december-31-2006-in-depth-with-punch-scan/#comments</comments>
		<pubDate>Sun, 31 Dec 2006 23:06:37 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=223</guid>
		<description><![CDATA[On this last day of 2006, it seemed fitting to (finally) post the conclusion to the voting security series (it was delayed due to an ear infection and my lack of desire to finalize the recording). Now, from sunny Key West, I wanted to make sure we ended the year strong. No end of year [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-december-31-2006-in-depth-with-punch-scan%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-december-31-2006-in-depth-with-punch-scan%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>On this last day of 2006, it seemed fitting to (finally) post the conclusion to the voting security series (it was delayed due to an ear infection and my lack of desire to finalize the recording). Now, from sunny Key West, I wanted to make sure we ended the year strong.</p>
<p>No end of year reflections, but in looking at the lessons learned, I realized that voting security and security in general have a lot more in common that we may realize at first glance. The good news, then, is that in 2007 we can continue to improve the way we practice security&#8230; and we may also be able to help improve the way our electronic voting systems work.</p>
<p>When listening to this interview, it may make sense to check out some of the diagrams and pictures from the punch scan website: <a target="_blank" href="http://www.punchscan.org/">www.punchscan.org</a></p>
<p>I really am impressed not only by the solution punch scan proposes, but by the energy and dedication of the punch scan team. I hope this solution is tested in 2007 and starts to gain more momentum. I plan to keep in touch with punch scan and support them as they continue to move forward.</p>
<p>I&#8217;m going to ring in the New Year wearing shorts and hanging out on the docks&#8230; and then I&#8217;ll be using some of the time here to think about and plan for the upcoming year. Expect more programming and more features designed to help you improve the way you explain and practice security in 2007. And expect to see the launch of the catalyst community (to support your efforts) as well as some additional programming, features and a book!</p>
<p>Yup, 2007 promises to be an exciting year for us all!</p>
<p>Thanks for your continued support, ideas, suggestions and passion. Especially your passion.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-december-31-2006-in-depth-with-punch-scan%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-december-31-2006-in-depth-with-punch-scan%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-december-31-2006-in-depth-with-punch-scan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst 38 &#124; Voting Security Mini-Series Gets Launched &#8211; 3 Things I Learned from &#8216;Hacking Democracy&#8217;</title>
		<link>http://www.securitycatalyst.com/security-catalyst-38-voting-security-mini-series-gets-launched-3-things-i-learned-from-hacking-democracy/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-38-voting-security-mini-series-gets-launched-3-things-i-learned-from-hacking-democracy/#comments</comments>
		<pubDate>Thu, 23 Nov 2006 06:35:43 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Security 2.0]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=202</guid>
		<description><![CDATA[Now that the elections are over, I figured it was a good time to step up the programming of the podcast by introducing some mini-series. I think mini-series will provide us the opportunity to pick topics that matter and dive a bit deeper. At least, we&#8217;re going to give it a try&#8230; feedback welcomed. To [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-38-voting-security-mini-series-gets-launched-3-things-i-learned-from-hacking-democracy%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-38-voting-security-mini-series-gets-launched-3-things-i-learned-from-hacking-democracy%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Now that the elections are over, I figured it was a good time to step up the programming of the podcast by introducing some mini-series. I think mini-series will provide us the opportunity to pick topics that matter and dive a bit deeper. At least, we&#8217;re going to give it a try&#8230; feedback welcomed.</p>
<p>To kick it off, I figured we could start by looking at the security around electronic voting. Yea, I know, the elections are over. To me, that makes for perfect timing. Less stress right now, and a good time for our profession to think about how we can help to improve the process.</p>
<p>Here are some links as mentioned in the podcast:</p>
<p><strong>Google Video</strong></p>
<p><a target="_blank" href="http://www.hbo.com/docs/programs/hackingdemocracy/?ntrack_para1=leftnav_category7_show1">Hacking Democracy</a> (http://www.hbo.com/docs/programs/hackingdemocracy/?ntrack_para1=leftnav_category7_show1)<br />
HRM! It seems to have been removed from Google Video. Well, it&#8217;s still being aired on HBO &#8211; so hopefully you will get a chance to see a copy. It&#8217;s worth the watch!<br />
<strong>Site to See</strong></p>
<p><a target="_blank" href="http://www.securosis.com/">Securosis</a> (http://www.securosis.com/)<br />
<a target="_blank" href="http://securosis.com/about/">Rich Mogul&#8217;s Bio</a> (http://securosis.com/about/)</p>
<p><strong>Voting Stories and Links</strong></p>
<p><a target="_blank" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9005063&#038;source=rss_topic84">E-voting 2006: A touch screen, a missing vote, a mystery in Arkansas </a>(http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9005063&#038;source=rss_topic84)</p>
<p>Questions we can help answer? Stories you want me to explore? Cheers or Jeers? send me an email: &#115;e&#99;&#117;ri&#116;yc&#97;&#116;al&#121;&#115;&#116;&#64;g&#109;a&#105;&#108;&#46;co&#109;.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-38-voting-security-mini-series-gets-launched-3-things-i-learned-from-hacking-democracy%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-38-voting-security-mini-series-gets-launched-3-things-i-learned-from-hacking-democracy%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-38-voting-security-mini-series-gets-launched-3-things-i-learned-from-hacking-democracy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst 37 &#8211; The FBI asks for help&#8230; so let&#8217;s help!</title>
		<link>http://www.securitycatalyst.com/security-catalyst-37-the-fbi-asks-for-help-its-time-for-us-to-help-them-help-themselves/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-37-the-fbi-asks-for-help-its-time-for-us-to-help-them-help-themselves/#comments</comments>
		<pubDate>Tue, 31 Oct 2006 03:35:28 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=186</guid>
		<description><![CDATA[In this episode, we explore how we can effectively partner with the FBI to share information in the form of a CONVERSATION where everyone who participates gains. I lay out three steps that I think we should discuss to improve this process. I look forward to your feedback. Sites to See http://www.changethis.com/ Some of the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-37-the-fbi-asks-for-help-its-time-for-us-to-help-them-help-themselves%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-37-the-fbi-asks-for-help-its-time-for-us-to-help-them-help-themselves%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>In this episode, we explore how we can effectively partner with the FBI to share information in the form of a CONVERSATION where everyone who participates gains. I lay out three steps that I think we should discuss to improve this process. I look forward to your feedback.</p>
<p><strong>Sites to See</strong></p>
<p><a target="_blank" href="http://www.changethis.com/">http://www.changethis.com/</a></p>
<p>Some of the recent manifestos that I have read and enjoyed:</p>
<p>http://www.changethis.com/19.CreativeGeneralist</p>
<p>Actually, there are many on the list, and while reviewing the site again today, I downloaded and printed a few off. Many good things here to read and consider. Heck, we should consider submitting Security 2.0. Anyone want to write with me?<br />
<strong>News Articles About the FBI Announcement</strong></p>
<p><a target="_blank" href="http://www.informationweek.com/story/showArticle.jhtml?articleID=193402056&#038;cid=RSSfeed_IWK_Security">Cybercrime High On FBI Priority List; Help Wanted</a></p>
<p><a target="_blank" href="http://www.eweek.com/article2/0,1759,2036619,00.asp?kc=EWRSS03129TX1K0000614">FBI: Companies Need to Report Cyber Attacks</a></p>
<p>As you know, I am a strong supporter of the FBI and have suggested three ways that we all need to work together to make a difference.</p>
<p>1- We need to bring together academic, private and public sectors and begin a real dialogue about how to measure the effectiveness of security. We have enough brain power and models available. The time has come to advance real solutions. When we have a better model, we can work to share more information.</p>
<p>2- We need a taxonomy. We need an &#8220;open-source&#8221; style taxonomy that covers the breadth and depth of knowledge and experiences that we would need to cover. As we launch the community, I hope to advance this. I look forward to your help.</p>
<p>3 -We need a way to mutually share information. I listed out a variety of ways and will be testing one in my local infragard in the coming months. Stay tuned!</p>
<p><em>Updated Note: The episode doesn&#8217;t seem to be including in the feed. I&#8217;m trying to figure out why and should have it fixed tonight or tomorrow morning. </em>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-37-the-fbi-asks-for-help-its-time-for-us-to-help-them-help-themselves%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-37-the-fbi-asks-for-help-its-time-for-us-to-help-them-help-themselves%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-37-the-fbi-asks-for-help-its-time-for-us-to-help-them-help-themselves/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Round Table &#8211; Episode 5 &#8211; Security of VoIP in the Enterprise</title>
		<link>http://www.securitycatalyst.com/security-round-table-episode-5-security-of-voip-in-the-enterprise/</link>
		<comments>http://www.securitycatalyst.com/security-round-table-episode-5-security-of-voip-in-the-enterprise/#comments</comments>
		<pubDate>Tue, 03 Oct 2006 03:29:51 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=179</guid>
		<description><![CDATA[Join us for our fifth exciting episode of the Security Round Table. Our special guest (and now newest member) is Dan York from: Blue Box: The VoIP Security Podcast. In this episode, we look at the general overview of VoIP technologies and the security risks &#8211; as well as the myths. Dan is a true [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-round-table-episode-5-security-of-voip-in-the-enterprise%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-round-table-episode-5-security-of-voip-in-the-enterprise%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Join us for our fifth exciting episode of the Security Round Table. Our special guest (and now newest member) is Dan York from: <a href="http://www.blueboxpodcast.com/2006/09/blue_box_40_voi.html">Blue Box: The VoIP Security Podcast</a>. In this episode, we look at the general overview of VoIP technologies and the security risks &#8211; as well as the myths.</p>
<p>Dan is a true expert and instructor on this topic &#8211; and school was definitely in for the SRT team!</p>
<p>Joining in on this episode:</p>
<p>Paul Asadorian | <a target="_blank" href="http://pauldotcom.com/">Pauldotcom Security Weekly</a><br />
Martin McKeay  | <a target="_blank" href="http://www.mckeay.net/secure/">Network Security Podcast</a><br />
Larry Pesce | <a target="_blank" href="http://pauldotcom.com/">Pauldotcom Security Weekly</a><br />
Michael Santarcangelo | <a target="_blank" href="http://www.securitycatalyst.com/">The Security Catalyst</a><br />
Alan Shimel | <a target="_blank" href="http://www.stillsecureafteralltheseyears.com/ashimmy/">SSAATY (Still Secure After All These Years)</a><br />
Dan York | <a target="_blank" href="http://www.blueboxpodcast.com/">Blue Box: The VoIP Security Podcast</a></p>
<p>**Note &#8211; soon I you will only be able to get this podcast by subscribing to the SRT podcast ***
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-round-table-episode-5-security-of-voip-in-the-enterprise%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-round-table-episode-5-security-of-voip-in-the-enterprise%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-round-table-episode-5-security-of-voip-in-the-enterprise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst 36 &#8211; SPECIAL REPORT: Did Two Factor Authentication Really Fail?</title>
		<link>http://www.securitycatalyst.com/security-catalyst-36-special-report-did-two-factor-authentication-really-fail/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-36-special-report-did-two-factor-authentication-really-fail/#comments</comments>
		<pubDate>Wed, 27 Sep 2006 23:32:23 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Security 2.0]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=176</guid>
		<description><![CDATA[Welcome back! Yeah, I know, that&#8217;s better said to me than by me. The complications of travel, life and podcasting have conspired against me, but not dimished my passion, the expansion of the blog or the re-creation of the catalyst community. In this episode, I introduce a new segment: &#8220;sites to see&#8221; and start pointing [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-36-special-report-did-two-factor-authentication-really-fail%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-36-special-report-did-two-factor-authentication-really-fail%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Welcome back! Yeah, I know, that&#8217;s better said to me than by me. The complications of travel, life and podcasting have conspired against me, but not dimished my passion, the expansion of the blog or the re-creation of the catalyst community.</p>
<p>In this episode, I introduce a new segment: &#8220;sites to see&#8221; and start pointing out security and security 2.0 websites to use.</p>
<p><em><strong>This weeks Site to See</strong></em></p>
<p><strong>Microsoft Security Advisories<br />
</strong><a target="_blank" href="http://www.microsoft.com/technet/security/advisory/default.mspx">http://www.microsoft.com/technet/security/advisory/default.mspx </a></p>
<p>You can learn why I think it&#8217;s worth checking out by listening to the podcast. If you have a suggestion for future sites to see (your own or something you think is valuable), send me your idea (and get credit) by email: <a target="_blank" href="&#109;ai&#108;&#116;&#111;&#58;&#115;e&#99;&#117;ri&#116;&#121;&#99;&#97;&#116;&#97;l&#121;&#115;t&#64;&#103;m&#97;i&#108;&#46;&#99;o&#109;?subject=site%20to%20see">s&#101;cu&#114;&#105;t&#121;c&#97;&#116;&#97;ly&#115;&#116;&#64;g&#109;&#97;&#105;l.&#99;o&#109;</a>.<br />
<em><strong>Special Report</strong></em><br />
Did Two Factor Really Fail?</p>
<p>The short answer is: no &#8211; listen to learn what could have been done differently and why you should care!</p>
<p><em><strong>Special Offer</strong></em><br />
I am offering a substantial discount to the first few people who want to improve the way their company addresses compliance and security (while making themselves look like rockstars) as I am about to unveil Effective Assurance. Listen to the podcast for details &#8211; or send me an email at <a target="_blank" href="&#109;&#97;il&#116;&#111;:m&#105;chael&#46;&#97;&#115;&#115;ur&#97;n&#99;e&#64;&#98;&#97;ld&#115;e&#99;&#117;rityexp&#101;&#114;&#116;&#46;co&#109;?subject=Effective%20Assurance%20Request">&#109;i&#99;&#104;ael.a&#115;&#115;ura&#110;&#99;e&#64;bal&#100;&#115;&#101;&#99;&#117;&#114;i&#116;&#121;&#101;xper&#116;.&#99;o&#109;</a> &#8212; I look forward to sharing my passion with you and helping you improve compliance through security without wasting another dollar!</p>
<p>**** 17 Days and the Catalyst Community is OPEN!! ****
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-36-special-report-did-two-factor-authentication-really-fail%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-36-special-report-did-two-factor-authentication-really-fail%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-36-special-report-did-two-factor-authentication-really-fail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SRT Episode 4 &#8211; Responsible Reporting of Breaches</title>
		<link>http://www.securitycatalyst.com/srt-episode-4-responsible-reporting-of-breaches/</link>
		<comments>http://www.securitycatalyst.com/srt-episode-4-responsible-reporting-of-breaches/#comments</comments>
		<pubDate>Sun, 17 Sep 2006 20:23:23 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=166</guid>
		<description><![CDATA[How many times have you wondered what you would do if you find out your company wasn&#8217;t protecting information as they promised? What if you were a consultant or contractor? Is there a right way to report on privacy and security breaches? Join the Security Round Table with Special Guest Randal Schwartz to discuss this [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt-episode-4-responsible-reporting-of-breaches%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt-episode-4-responsible-reporting-of-breaches%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>How many times have you wondered what you would do if you find out your company wasn&#8217;t protecting information as they promised? What if you were a consultant or contractor?</p>
<p>Is there a right way to report on privacy and security breaches?</p>
<p>Join the Security Round Table with Special Guest Randal Schwartz to discuss this important issue.</p>
<p>On this episode:</p>
<p>Larry Pesce | <a target="_blank" href="http://www.pauldotcom.com/">Pauldotcom Security Weekly</a> | <a target="_blank" href="http://www.haxorthematrix.com/">Haxor the Matrix</a><br />
Martin McKeay | <a target="_blank" href="http://www.mckeay.net/">Network Security Blog &#038; Podcast</a><br />
Michael Santarcangelo | <a target="_blank" href="http://www.securitycatalyst.com/">The Security Catalyst</a><br />
Randal Schwartz | <a target="_blank" href="http://www.stonehenge.com/merlyn/">Stonehenge</a> | <a target="_blank" href="http://www.lightlink.com/spacenka/fors/">Legal Information: Friends of Randal Schwartz</a><br />
<em /></p>
<p><em>Note: we did reach some interesting conclusions and directions for future advancement. Continue the discussion at the <a target="_blank" href="http://community.securitycatalyst.com/">Security Catalyst Community</a> (currently open to trusted catalysts until October 15, 2006 when it becomes available to the entire community). </em>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt-episode-4-responsible-reporting-of-breaches%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt-episode-4-responsible-reporting-of-breaches%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/srt-episode-4-responsible-reporting-of-breaches/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Catalyst &#8211; 35 &#8211; Introducting Security 2.0</title>
		<link>http://www.securitycatalyst.com/security-catalyst-35-introducting-security-20/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-35-introducting-security-20/#comments</comments>
		<pubDate>Tue, 29 Aug 2006 04:09:06 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=156</guid>
		<description><![CDATA[Recorded! From a hotel room in Phoenix (sure, it&#8217;s hot, but it&#8217;s a dry heat &#8211; try taking a tumble in your clothes dryer)&#8230; it&#8217;s another Security Catalyst Podcast (I know, about time!). I&#8217;m actually excited to share something I&#8217;ve been quietly working on now for over a year &#8211; the evolution of security I [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-35-introducting-security-20%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-35-introducting-security-20%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Recorded! From a hotel room in Phoenix (sure, it&#8217;s hot, but it&#8217;s a dry heat &#8211; try taking a tumble in your clothes dryer)&#8230; it&#8217;s another Security Catalyst Podcast (I know, about time!).</p>
<p>I&#8217;m actually excited to share something I&#8217;ve been quietly working on now for over a year &#8211; the evolution of security I have been calling Security 2.0. Wait! Look past the name and check out what I think the future for information security holds. I have started to collaborate with Ron Woerner on what this would entail, and we have submitted a proposal to speak at RSA 2007 in February &#8211; if selected, we hope that will be where the concepts really get grounded and introduced.</p>
<p>Until then, you can count on Ron and I to start to advance the concepts and the ideas covered in Security 2.0. Basically, security 2.0 comes down to three elements:</p>
<ul>
<li>leveraging web 2.0 to improve the way we practice information security</li>
<li>taking the knowledge we have and securing web 2.0 offerings</li>
<li>the tools, skills, attitudes and experiences of a Security 2.0 professional</li>
</ul>
<p>Basically, I believe it&#8217;s time to completely shift the way we <em><strong>practice</strong></em> information security. We have to change the focus, make it more convenient, more simple and more, well, secure. It&#8217;s not that simple &#8211; but in this podcast, I introduce the concepts in a condensed fashion. More details will emerge and evolve in the coming weeks and months.</p>
<p>I look forward to your ideas, insights, passions and excitement as we work together to celebrate the positives and truly blaze a new trail in the future of information security. By learning our history and studying other fields, we will advance!</p>
<p>If you&#8217;re new to Web 2.0, here are some links to get you started:</p>
<p>Start Here: <span id="intelliTxt" /></p>
<h2>What Is Web 2.0</h2>
<p><a target="_blank" href="http://www.oreillynet.com/pub/a/oreilly/tim/news/2005/09/30/what-is-web-20.html">http://www.oreillynet.com/pub/a/oreilly/tim/news/2005/09/30/what-is-web-20.html</a></p>
<p>This is a good summary:<a target="_blank" href="http://www.squidoo.com/introtoweb20/"> http://www.squidoo.com/introtoweb20/ </a></p>
<p>I found this useful, too: <a target="_blank" href="http://en.wikipedia.org/wiki/Web_2">http://en.wikipedia.org/wiki/Web_2</a></p>
<p>As we prepare to relaunch the Security Catalyst Community, we&#8217;ll incorporate a section for Security 2.0 so we can work collaboratively, leveraging Web 2.0 tools (!) to evolve this concept.</p>
<p align="center"><em><strong>Help spread the word by linking to the Security Catalyst and share these ideas and concepts with others!</strong></em></p>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-35-introducting-security-20%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-35-introducting-security-20%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-35-introducting-security-20/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Listen to the experts, um, discuss &#8220;NAC&#8221; (An SRT special edition!)</title>
		<link>http://www.securitycatalyst.com/srt_nac/</link>
		<comments>http://www.securitycatalyst.com/srt_nac/#comments</comments>
		<pubDate>Mon, 14 Aug 2006 13:59:02 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=150</guid>
		<description><![CDATA[Network Access Control, or NAC, is a hot and important topic these days. Recently, some of the experts in the industry starting a discussion via their blogs&#8230; Martin McKeay then suggested they take it to the Security Roundtable and talk it through. Thanks to the efforts of the team, we can all be smarter when [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt_nac%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt_nac%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Network Access Control, or NAC, is a hot and important topic these days. Recently, some of the experts in the industry starting a discussion via their blogs&#8230; Martin McKeay then suggested they take it to the Security Roundtable and talk it through.</p>
<p>Thanks to the efforts of the team, we can all be smarter when it comes to NAC. You can listen to the result on the SRT website, here: http://www.securityroundtable.com/ or I included the link in the feed. Martin claims he was an innocent bystander. I don&#8217;t understand the claim of innocence <img src='http://www.securitycatalyst.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
We&#8217;re scheduled to record another SRT this week, this time looking at the actions and impact/fallout of the AOL blunder. We&#8217;ve also got several more topics sure to impact our thinking in the trenches lined up for the coming weeks&#8230;
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt_nac%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt_nac%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/srt_nac/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catlayst 34 &#8211; Interview with Greg and Terry from Always Known As (AKA)</title>
		<link>http://www.securitycatalyst.com/sc34/</link>
		<comments>http://www.securitycatalyst.com/sc34/#comments</comments>
		<pubDate>Thu, 10 Aug 2006 06:24:08 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=148</guid>
		<description><![CDATA[Welcome to Security Catalyst 34! I am excited to bring you an interview with a Web 2.0 company that has incorporated security and privacy into their solution from the very beginning&#8230; Always Known As (AKA). Join me as I discuss their efforts and talk security and the future of digital ID management with Greg and [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc34%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc34%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Welcome to Security Catalyst 34! I am excited to bring you an interview with a Web 2.0 company that has incorporated security and privacy into their solution from the very beginning&#8230; <a target="_blank" href="https://www.alwaysknownas.com/index.php?pr=1">Always Known As (AKA)</a>. Join me as I discuss their efforts and talk security and the future of digital ID management with Greg and Terry.</p>
<p>I recorded this from a hotel room in Phoenix, Arizona &#8211; which is why it&#8217;s a bit later than expected. I have more podcasts recorded, lined up and ready to be edited and released and will work to get back on track.</p>
<p>I&#8217;ve also been busy planning to new security catalyst community, the trusted catalyst designation and a new way for us to learn and practice security that I hope to roll out this fall &#8211; we have a lot going on!</p>
<p>After you listen this week, let me know what you think of AKA and what questions you would like me to ask. If there is enough interest, I&#8217;ll work to resume our teleconferences/skypecasts (probably for the Trusted Catalysts) in September where we will all have the opportunity to speak with Terry and Greg about AKA directly!</p>
<p>My AKA: Michael</p>
<p>I look forward to your comments and your continued efforts. I have some exciting programs planned that I&#8217;ll be releasing in the coming months. Keep making a difference!!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc34%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc34%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/sc34/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Security Round Table &#8211; Episode 3 &#8211; Liability for Vulnerabilities and Responsible Reporting</title>
		<link>http://www.securitycatalyst.com/srt3/</link>
		<comments>http://www.securitycatalyst.com/srt3/#comments</comments>
		<pubDate>Fri, 21 Jul 2006 20:17:34 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=143</guid>
		<description><![CDATA[I am excited to present to you the SRT&#8217;s third episode. The goal of these podcasts is simple: bring together podcasters and occassional guests to discuss important security topics. This episode had some great (read: diverse) representation as we tackled the issue of who should be responsible for vulnerable code and &#8220;good practices&#8221; around notification, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt3%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt3%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I am excited to present to you the SRT&#8217;s third episode. The goal of these podcasts is simple: bring together podcasters and occassional guests to discuss important security topics. This episode had some great (read: diverse) representation as we tackled the issue of who should be responsible for vulnerable code and &#8220;good practices&#8221; around notification, patching and the like.</p>
<p>This podcast went a bit longer than planned, and I suspect we could have kept talking all night long! I personally learned quite a bit and enjoyed the opportunity to explore some of these issues and hear different perspectives. I hope you enjoy it too!</p>
<p>Joining us on this effort was:<br />
Martin McKeay (<a target="_blank" href="http://www.mckeay.net/secure/">The Network Security Podcast</a>)<br />
Paul Asadorian (<a target="_blank" href="http://www.pauldotcom.com/">Pauldotcom Security Weekly</a>)<br />
Jamal Khan (<a target="_blank" href="http://usp.hdaar.com/rss/radio.xml">Hdaar Security Radio</a>)<br />
Alan Shimmel (<a target="_blank" href="http://ashimmy.typepad.com/ashimmy/">Still Secure, After All These Years</a>)<br />
Ron Woerner (Security Catalyst Contributor)</p>
<p>Ideas? Comments? Suggestions? &#115;e&#99;u&#114;&#105;&#116;&#121;&#99;at&#97;&#108;&#121;st&#64;&#103;mail&#46;c&#111;&#109;</p>
<p>Michael (<a target="_blank" href="http://www.securitycatalyst.com/">The Security Catalyst</a>)
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt3%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt3%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/srt3/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Catalyst 33 &#8211; Insider Interviews &#8211; The FBI Innocent Images Program</title>
		<link>http://www.securitycatalyst.com/sc33/</link>
		<comments>http://www.securitycatalyst.com/sc33/#comments</comments>
		<pubDate>Tue, 18 Jul 2006 15:48:01 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=137</guid>
		<description><![CDATA[As a father, I know that protecting my children and keeping them safe as they grow and develop is important. In today&#8217;s world, that extends to the way that we and our children use the Internet, as well as teaching them about the predators that lurk in the shadows. On this important episode of the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc33%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc33%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>As a father, I know that protecting my children and keeping them safe as they grow and develop is important. In today&#8217;s world, that extends to the way that we and our children use the Internet, as well as teaching them about the predators that lurk in the shadows.</p>
<p>On this important episode of the Security Catalyst, we are joined by FBI Special Agent David Fallon and Police Officer Jonathan Lester &#8211; part of the FBI Innocent Images program. In addition to educating us about their efforts, they share simple tips and strategies that we should all be following to protect our children, as well as ways that we can get involved to help (without harming their efforts).</p>
<p>Here is the listing of resources mentioned on the podcast. I will continue to update and expand this page (especially with your help and suggestions): <a target="_blank" href="http://www.securitycatalyst.com/protect-children/">http://www.securitycatalyst.com/protect-children/</a></p>
<p>Based on this interview, I have started research and looking for some additional interviews to provide us with some insights on how to coach our children through this important process, the steps we need to take to protect our children and ourselves, the ways we can get involved. If you want to contribute, please send me an email.</p>
<p><em>Please consider sharing this program with others (tell them to check out http://www.securitycatalyst.com/2006/07/18/sc33/) and use the buttons on your right to subscribe so you don&#8217;t miss any future content.</em>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc33%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc33%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/sc33/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Round Table &#8211; Episode 2 &#8211; What to do about stolen laptops and Privacy in the EU</title>
		<link>http://www.securitycatalyst.com/srt2/</link>
		<comments>http://www.securitycatalyst.com/srt2/#comments</comments>
		<pubDate>Sun, 25 Jun 2006 04:07:12 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=128</guid>
		<description><![CDATA[We recorded the second episode of the Security Roundtable last week &#8211; and it is now available for your listening pleasure! On this episode, I was joined by SRT founding member Martin McKeay of the Network Security Podcast and special guest Alan Shimel from the Still Secure podcast. We had a really engaging conversation about [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt2%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>We recorded the second episode of the <a target="_blank" href="http://www.securityroundtable.com">Security Roundtable</a> last week &#8211; and it is now available for your listening pleasure! On this episode, I was joined by SRT founding member Martin McKeay of the <a target="_blank" href="http://www.mckeay.net/secure/">Network Security Podcast</a> and special guest Alan Shimel from the <a target="_blank" href="http://ashimmy.typepad.com/about.html">Still Secure podcast</a>.</p>
<p>We had a really engaging conversation about the recent laptop thefts and explored what has to be done about it, as well as expressed some opinions about the current actions. We talk about technical and non-technical solutions to address these issues.</p>
<p>We then explored the differences between the US and the European Union in terms of data privacy, breaches and breach reporting. I would really enjoy learning your opinion and hope you send me some feedback (until the forums/community is restored) &#8212; sec&#117;r&#105;&#116;&#121;c&#97;&#116;&#97;ly&#115;t&#64;&#103;&#109;ail&#46;co&#109;.</p>
<p>Keep making a difference!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsrt2%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/srt2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst 32 &#8211; Three Steps to Reduce Laptop Thefts (and Protect Data)</title>
		<link>http://www.securitycatalyst.com/sc32/</link>
		<comments>http://www.securitycatalyst.com/sc32/#comments</comments>
		<pubDate>Sun, 18 Jun 2006 19:10:14 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=124</guid>
		<description><![CDATA[Happy Father&#8217;s Day! In reflecting on the lessons I learned (and continue to learn!) from my father (thanks, Dad!), I was considering the recent data breaches we have witnessed as a result of laptop (and other) theft. The reactions have been predictable and focus on finger pointing, passing the blame and then looking for the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc32%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc32%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Happy Father&#8217;s Day!</p>
<p>In reflecting on the lessons I learned (and continue to learn!) from my father (thanks, Dad!), I was considering the recent data breaches we have witnessed as a result of laptop (and other) theft. The reactions have been predictable and focus on finger pointing, passing the blame and then looking for the magical silver bullet that will solve the problems.</p>
<p>I think the solutions don&#8217;t start with technology, but rather start by addressing personal responsibility and accountability. From that basis, we are able to make better decisions and provide strong foundations on which to build our solutions.</p>
<p>In this podcast, I share with you some of the lessons I have learned in how we can affect this change. I share with you my experience and look forward to your contributions in the catalyst community.</p>
<p>I also share some of the listener survey results; great stuff for me, perhaps not as exciting for you. Thanks to your help, reviews and subscriptions, I have a healthy sense of what you expect and pledge to continue to improve and provide good value to you. If you want to know what&#8217;s coming ahead or provide feedback, please check the forums. And you are always welcome to send me an email, but for the next few months, I&#8217;m going to focus on programming.</p>
<p>If you&#8217;d like to explore or challenge the concepts I introduced today, <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=399">please contribute to this thread in the forums</a>.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc32%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc32%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/sc32/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Catlayst 31 &#8211; Interview with Scott Barlow from Reflexion</title>
		<link>http://www.securitycatalyst.com/reflexion/</link>
		<comments>http://www.securitycatalyst.com/reflexion/#comments</comments>
		<pubDate>Sun, 11 Jun 2006 19:11:06 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=122</guid>
		<description><![CDATA[I&#8217;m passionate about security, but also in exploring new solutions to the problems we face. Lately I&#8217;ve been exploring the economics of spam, and looking into ways we can disrupt the economics of spam in an effort to reduce it. During our first Security Round Table podcast, we talked about spam, and I mentioned that [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Freflexion%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Freflexion%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I&#8217;m passionate about security, but also in exploring new solutions to the problems we face. Lately I&#8217;ve been exploring the economics of spam, and looking into ways we can disrupt the economics of spam in an effort to reduce it. During our first Security Round Table podcast, we talked about spam, and I mentioned that I was interested in disposable email addresses &#8211; and asked for links to companies that could do it.</p>
<p>A few days later, I came across <a target="_blank" href="http://www.reflexion.net/">Reflexion</a>, a company with a different approach to reducing spam, since they use what they call &#8220;non-disposable&#8221; email addresses. I called and shared some good technical discussions, and then decided to interview Scott Barlow about their solution.</p>
<p>Now this marks the first time I have interviewed a vendor about their solution. I took an approach of asking the questions I would ask them if I were going to consider them for my company or on behalf of a client. I hope you find this useful, and if so, I will look for other noteworthy solutions to share with you.</p>
<p>Either way, let me know &#8211; and <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=392">ask more questions in our forum in this thread (click on the link)</a>.</p>
<p>In the podcast, Scott mentions a <a target="_blank" href="http://www.reflexion.net/_assets/img/RTC4-Message_Flow.jpg">link to a diagram, here is the diagram</a>.</p>
<p>Also, here are some of the recent threads on the forums that I would enjoy your feedback on:</p>
<p><a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=338">Certs, Degrees, And Stuff, The Professionalizing of the IT Industry</a></p>
<p><a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=389">Security Blogs And Forums</a></p>
<p><a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=364">What Are The First 5 Actions, Security Catalyst Case Study &#8211; Baselines </a></p>
<p><a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=363">Wireless Security: Protecting Your Company (Westchester County, NY)</a></p>
<p>Promo: <a target="_blank" href="http://www.mightyseek.com/">The Mighty Seek Podcast</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Freflexion%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Freflexion%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/reflexion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst 30 (Insider Interviews) Botnets, part II with Jim Lippard</title>
		<link>http://www.securitycatalyst.com/botnets-pt2/</link>
		<comments>http://www.securitycatalyst.com/botnets-pt2/#comments</comments>
		<pubDate>Sat, 03 Jun 2006 20:15:17 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=118</guid>
		<description><![CDATA[Join us for Episode 30; we conclude our interview with Jim Lippard and discuss what is being done to combat botnets, as well as what we can or should be doing. Jim has joined the forums and has been answering questions in the Episode 29&#038;30 thread. Please join in and ask your questions, share your [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fbotnets-pt2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fbotnets-pt2%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Join us for Episode 30; we conclude our interview with Jim Lippard and discuss what is being done to combat botnets, as well as what we can or should be doing.</p>
<p>Jim has joined the forums and has been answering questions in the <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=378">Episode 29&#038;30 thread</a>. Please join in and ask your questions, share your ideas or help explore how we can make a difference.</p>
<p>Information about <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=379">Trusted Catalysts can be found here</a>.</p>
<p>It&#8217;s not too late to contribute to the Catalyst Survey and suggest how I can improve. <a target="_blank" href="http://www.surveymonkey.com/s.asp?u=817982146743">Click here to take the survey. </a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fbotnets-pt2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fbotnets-pt2%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/botnets-pt2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Round Table &#8211; Episode 1 &#8211; Email Security</title>
		<link>http://www.securitycatalyst.com/security-round-table-episode-1-email-security/</link>
		<comments>http://www.securitycatalyst.com/security-round-table-episode-1-email-security/#comments</comments>
		<pubDate>Thu, 25 May 2006 21:17:45 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=116</guid>
		<description><![CDATA[Listen in as Martin McKeay (Network Security), Dan Kuykendal (Mighty Seek), Larry Pesce (Pauldotcom Security) and Michael Santarcangelo (The Security Catalyst) discuss email security during the first Security Round Table. We recorded the podcast from a conference bridge, so the quality is about what you would expect from the broadcast radio. This is our first [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-round-table-episode-1-email-security%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-round-table-episode-1-email-security%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><img align="left" title="SRT" id="image131" alt="SRT" src="http://www.securitycatalyst.com/wp-content/uploads/2006/05/srtlogo.thumbnail.jpg" />Listen in as Martin McKeay (<a target="_blank" href="http://www.mckeay.net/secure/">Network Security</a>), Dan Kuykendal (<a target="_blank" href="http://www.mightyseek.com/">Mighty Seek</a>), Larry Pesce (<a target="_blank" href="http://pauldotcom.com/">Pauldotcom Security</a>) and Michael Santarcangelo (<a target="_blank" href="http://www.securitycatalyst.com/">The Security Catalyst</a>) discuss email security during the first Security Round Table. We recorded the podcast from a conference bridge, so the quality is about what you would expect from the broadcast radio.</p>
<p>This is our first effort &#8211; and I learned some ideas that I wrote down, and hope you do, too! Please send us feedback and let us know what other topics you would like for us to cover.</p>
<p>Check out more at the <a target="_blank" href="http://www.securityroundtable.com/">Security Round Table</a>.</p>
<p>Please send me feedback and suggestions to se&#99;u&#114;&#105;&#116;y&#99;a&#116;&#97;&#108;&#121;s&#116;&#64;&#103;&#109;&#97;&#105;l&#46;&#99;o&#109;</p>
<p>Discuss this episode with others here in <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=381">The Security Catalyst Forums</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-round-table-episode-1-email-security%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-round-table-episode-1-email-security%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-round-table-episode-1-email-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst 29 (Insider Interviews) &#8211; Botnets with Jim Lippard, Part I</title>
		<link>http://www.securitycatalyst.com/botnets-pt1/</link>
		<comments>http://www.securitycatalyst.com/botnets-pt1/#comments</comments>
		<pubDate>Tue, 23 May 2006 18:49:53 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=112</guid>
		<description><![CDATA[We&#8217;ve all heard the term &#8220;botnet &#8212; and have even seen the recent arrests,successful trials and sentencing of botnet &#8220;herders.&#8221; So what exactly are botnets, how do they affect us and why should we care? Jim Lippard joins us to share his insights on how botnets work, and helps us understand why they are continuing [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fbotnets-pt1%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fbotnets-pt1%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>We&#8217;ve all heard the term &#8220;botnet &#8212; and have even seen the recent arrests,successful trials and sentencing of botnet &#8220;herders.&#8221; So what exactly are botnets, how do they affect us and why should we care?</p>
<p>Jim Lippard joins us to share his insights on how botnets work, and helps us understand why they are continuing to grow at an alarming rate. Listen to this first of two interviews with Jim to understand the basics of botnets and get ready to learn how we can combat them on the next episode.</p>
<p>Please take 5 minutes to <a target="_blank" href="http://www.surveymonkey.com/s.asp?u=817982146743">complete the Security Catalyst Listener Survey</a> and help improve the program.</p>
<p><a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=378">Discuss Security Catalyst 29 and Botnets here</a>.</p>
<p><a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=379">Ideas and suggestions about Trusted Catalysts Here.</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fbotnets-pt1%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fbotnets-pt1%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/botnets-pt1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst 28 &#8211; The Practice of Information Security &#124; Influence the Future of the Catalyst</title>
		<link>http://www.securitycatalyst.com/sc28/</link>
		<comments>http://www.securitycatalyst.com/sc28/#comments</comments>
		<pubDate>Tue, 16 May 2006 20:56:55 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=109</guid>
		<description><![CDATA[After a brief and unintended break, I&#8217;m back. Actually the beginning of this episode is a bit of an explanation of what the last few weeks were like (basically, life, business and travel all collided). So we&#8217;re back &#8211; and starting around the 7 minute mark, I explain some insights I have gained on information [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc28%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc28%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>After a brief and unintended break, I&#8217;m back. Actually the beginning of this episode is a bit of an explanation of what the last few weeks were like (basically, life, business and travel all collided). So we&#8217;re back &#8211; and starting around the 7 minute mark, I explain some insights I have gained on information security and what we need to do to shift the culture of security.</p>
<p>In this episode, I also ask for your comments and insights on how to better focus and improve the security catalyst. If you could take a few minutes to respond to this survey (<a target="_blank" href="http://www.surveymonkey.com/s.asp?u=817982146743">PLEASE TAKE A MINUTE FOR TO COMPLETE THE SURVEY</a>) or share some ideas with me at &#115;ecur&#105;tycat&#97;&#108;&#121;&#115;&#116;&#64;&#103;&#109;ai&#108;&#46;co&#109;, I&#8217;d appreciate learning how I can better serve you.</p>
<p>Look for links and episode information in the forums here: <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=375">Discuss Security Catalyst 28</a></p>
<p>Learn about the Security Roundtable here: <a target="_blank" href="http://www.securityroundtable.com/">The Security Roundtable</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc28%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsc28%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/sc28/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst 27 (Wireless Law!, Compliance Advice, Your top 5?)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-27-wireless-law-compliance-advice-your-top-5/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-27-wireless-law-compliance-advice-your-top-5/#comments</comments>
		<pubDate>Thu, 27 Apr 2006 15:50:01 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=98</guid>
		<description><![CDATA[NOTE: due to an unexpected Feedburner error, we turned off the redirect and have begun the process of migrating away. This should not affect you if you are using iTunes &#8211; but please check your subscriptions. Thanks! Sorry if you get this twice. ===Begin Program === Welcome to episode 27 of the Security Catalyst Podcast! [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-27-wireless-law-compliance-advice-your-top-5%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-27-wireless-law-compliance-advice-your-top-5%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><em><strong>NOTE: due to an unexpected Feedburner error, we turned off the redirect and have begun the process of migrating away. This should not affect you if you are using iTunes &#8211; but please check your subscriptions. Thanks!</strong></em></p>
<p><em><strong>Sorry if you get this twice. </strong></em></p>
<p>===Begin Program ===</p>
<p>Welcome to episode 27 of the Security Catalyst Podcast! In this episode, we talk about the new wireless security law enacted by my neighbors in Westchester County, NY; I offer some advice and guidance on compliance (based on my experience) and then set up a case study to help us determine the steps we need to take when protecting our organizations.</p>
<p><img align="left" alt="criminal and lawyer.gif" id="image113" title="criminal and lawyer.gif" src="http://www.securitycatalyst.com/wp-content/uploads/2006/04/criminal%20and%20lawyer.thumbnail.gif" />The wireless law is an interesting one, and I look forward to leveraging our growing catalyst community to help provide the guidance necessary for this effort to be successful. In that same vein, we start with our security makeover series next week, and will be using the next 10 weeks to examine how to acheive compliance through security. This is a series that will benefit us all &#8211; and you will have a chance to be involved!</p>
<p>Based on a conversation I had yesterday, I wanted to pose a situation and then collectively determine the immediate actions we would take. The end result of this effort (over the next few months) will be a series of comprehensive (and validated!) baselines that we can use to shore up our efforts. More importantly, done right, other businesses and people new to security can learn from our experience, too!</p>
<p>I will post additional information and links in the forums -> and we can let the discussions begin!</p>
<p><a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=363">Discuss Security Catalyst 27 Here</a><br />
<a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=364">Discuss The First 5 Security Actions Here</a></p>
<p>Thanks for listening. Please tell a friend about our efforts and encourage them to subscribe!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-27-wireless-law-compliance-advice-your-top-5%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-27-wireless-law-compliance-advice-your-top-5%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-27-wireless-law-compliance-advice-your-top-5/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-27-20060427.mp3" length="17688030" type="audio/mpeg" />
			<itunes:keywords>Information Protection,Podcast</itunes:keywords>
		<itunes:subtitle>NOTE: due to an unexpected Feedburner error, we turned off the redirect and have begun the process of migrating away. This should not affect you if you are using iTunes - but please check your subscriptions. Thanks!  Sorry if you get this twice.</itunes:subtitle>
		<itunes:summary>NOTE: due to an unexpected Feedburner error, we turned off the redirect and have begun the process of migrating away. This should not affect you if you are using iTunes - but please check your subscriptions. Thanks!

Sorry if you get this twice. 

===Begin Program ===

Welcome to episode 27 of the Security Catalyst Podcast! In this episode, we talk about the new wireless security law enacted by my neighbors in Westchester County, NY; I offer some advice and guidance on compliance (based on my experience) and then set up a case study to help us determine the steps we need to take when protecting our organizations.

The wireless law is an interesting one, and I look forward to leveraging our growing catalyst community to help provide the guidance necessary for this effort to be successful. In that same vein, we start with our security makeover series next week, and will be using the next 10 weeks to examine how to acheive compliance through security. This is a series that will benefit us all - and you will have a chance to be involved!

Based on a conversation I had yesterday, I wanted to pose a situation and then collectively determine the immediate actions we would take. The end result of this effort (over the next few months) will be a series of comprehensive (and validated!) baselines that we can use to shore up our efforts. More importantly, done right, other businesses and people new to security can learn from our experience, too!

I will post additional information and links in the forums -&gt; and we can let the discussions begin!

Discuss Security Catalyst 27 Here
Discuss The First 5 Security Actions Here

Thanks for listening. Please tell a friend about our efforts and encourage them to subscribe!</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 26 &#8211; Insider Interviews &#8211; Randal Schwartz</title>
		<link>http://www.securitycatalyst.com/security-catalyst-26-insider-interviews-randal-schwartz/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-26-insider-interviews-randal-schwartz/#comments</comments>
		<pubDate>Fri, 21 Apr 2006 15:25:06 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[cissp]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[intel]]></category>
		<category><![CDATA[perl]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[santarcangelo]]></category>
		<category><![CDATA[schwartz]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=96</guid>
		<description><![CDATA[In late July 1995, a trial jury convicted Randal L. Schwartz of three felony counts under Oregon&#8217;s Computer Crime Law (learn more here). On this episode, we are joined by the legendary Randal Schwartz to discuss what happened to him, how you can prevent it from happening to you, and what we can all do [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-26-insider-interviews-randal-schwartz%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-26-insider-interviews-randal-schwartz%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>In late July 1995, a trial jury convicted Randal L. Schwartz of three felony counts under Oregon&#8217;s Computer Crime Law <a href="http://www.lightlink.com/spacenka/fors/" target="_blank">(learn more here)</a>. On this episode, we are joined by the legendary <a href="http://www.stonehenge.com/index.html" target="_blank">Randal Schwartz</a> to discuss what happened to him, how you can prevent it from happening to you, and what we can all do about it in the future.</p>
<p><img id="image111" title="justice" src="http://www.securitycatalyst.com/wp-content/uploads/2006/04/statue%20of%20woman%20holding%20swo.thumbnail.gif" alt="justice" align="left" />We will invite Randal back again in the future to talk about perl and application security &#8211; but I hope that you are able to enjoy this interview and learn how to protect yourself. The focus is not on the company Randal was working with, but with how broad laws can hurt &#8211; and the protections we should all have in place.</p>
<p>Randal has joined our forums to take part in any discussion about how to deal with laws like this, and how we can, as a community, make a difference. I look forward to your insights and experiences: <a href="http://forums.securitycatalyst.com/index.php?showtopic=352" target="_blank">Click here to go to the forums. </a></p>
<p>In case you missed the teleseminar on Tuesday, the information and discussion has started: <a href="http://forums.securitycatalyst.com/index.php?showtopic=348" target="_blank">Click Here to talk about &#8220;Free Security.&#8221; </a></p>
<p>I&#8217;d like to know what sites you use for &#8220;best practices.&#8221; Share your insights here: <a href="http://forums.securitycatalyst.com/index.php?showtopic=353" target="_blank">Security Best Practices </a></p>
<p>Thanks for listening. If you liked the show, tell a friend!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-26-insider-interviews-randal-schwartz%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-26-insider-interviews-randal-schwartz%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-26-insider-interviews-randal-schwartz/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcast/SC-26-20060421.mp3" length="19618181" type="audio/mpeg" />
			<itunes:keywords>catalyst,cissp,Information Protection,intel,perl,Podcast,santarcangelo,schwartz,security</itunes:keywords>
		<itunes:subtitle>In late July 1995, a trial jury convicted Randal L. Schwartz of three felony counts under Oregon&#039;s Computer Crime Law (learn more here). On this episode, we are joined by the legendary Randal Schwartz to discuss what happened to him,</itunes:subtitle>
		<itunes:summary>In late July 1995, a trial jury convicted Randal L. Schwartz of three felony counts under Oregon&#039;s Computer Crime Law (learn more here). On this episode, we are joined by the legendary Randal Schwartz to discuss what happened to him, how you can prevent it from happening to you, and what we can all do about it in the future.

We will invite Randal back again in the future to talk about perl and application security - but I hope that you are able to enjoy this interview and learn how to protect yourself. The focus is not on the company Randal was working with, but with how broad laws can hurt - and the protections we should all have in place.

Randal has joined our forums to take part in any discussion about how to deal with laws like this, and how we can, as a community, make a difference. I look forward to your insights and experiences: Click here to go to the forums. 

In case you missed the teleseminar on Tuesday, the information and discussion has started: Click Here to talk about &quot;Free Security.&quot; 

I&#039;d like to know what sites you use for &quot;best practices.&quot; Share your insights here: Security Best Practices 

Thanks for listening. If you liked the show, tell a friend!</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
		<itunes:duration>33:34</itunes:duration>
	</item>
		<item>
		<title>Security Catalyst 25 &#8211; Insider Interviews &#8211; Podslurping with Abe Usher</title>
		<link>http://www.securitycatalyst.com/security-catalyst-25-insider-interviews-podslurping-with-abe-usher/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-25-insider-interviews-podslurping-with-abe-usher/#comments</comments>
		<pubDate>Thu, 13 Apr 2006 16:15:23 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=92</guid>
		<description><![CDATA[When I first read the term podslurping, many things came to mind. My second reaction was along the lines of &#8220;we&#8217;ve known about the risk from USB and portable devices for a while, so what&#8217;s new?&#8221; Then I finally got around to reading the article and learning from Abe Usher why I needed a different [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-25-insider-interviews-podslurping-with-abe-usher%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-25-insider-interviews-podslurping-with-abe-usher%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>When I first read the term podslurping, many things came to mind. My second reaction was along the lines<img align="right" title="Bulldog" id="image107" alt="Bulldog" src="http://www.securitycatalyst.com/wp-content/uploads/2006/04/bulldog%205.thumbnail.gif" /> of &#8220;we&#8217;ve known about the risk from USB and portable devices for a while, so what&#8217;s new?&#8221; Then I finally got around to reading the article and learning from Abe Usher why I needed a different mindset.</p>
<p>It turns out that advancements in USB technology, combined with the improvement of the devices that use USB and the ever-growing storage capacity, in fact, pose a significant potential threat. We focus a lot of time and energy right now on perimeter protections and the like &#8211; and yet freely recognize insider threats are more damaging.</p>
<p>Abe Usher got the word out, and now he joins Security Catalyst to help change the way we think about end point security. Listen now to learn how podslurping can affect you &#8211; and what you can do about it today.<br />
<a target="_blank" href="http://www.securitycatalyst.com/podcasts/SC-25-20060413.mp3"><br />
</a></p>
<p>Learn more about podslurping from <a target="_blank" href="http://www.sharp-ideas.net/index.php">Abe Usher at his Sharp Ideas website</a>.</p>
<p>Continue the discussion and learn more about the technologies mentioned in the podcast in the <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=347">Security Catalyst Forums (click here)</a>.</p>
<p>The &#8220;Hot Topic&#8221; of the week is <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=338">Certs, Degrees, And Stuff, The Professionalizing of the IT Industry &#8212; join in the conversation</a>!<br />
Join us next week for an insightful interview with <a target="_blank" href="http://www.stonehenge.com/merlyn/">Randal Schwartz</a>!!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-25-insider-interviews-podslurping-with-abe-usher%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-25-insider-interviews-podslurping-with-abe-usher%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-25-insider-interviews-podslurping-with-abe-usher/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-25-20060413.mp3" length="16573845" type="audio/mpeg" />
			<itunes:keywords>Information Protection,Podcast</itunes:keywords>
		<itunes:subtitle>When I first read the term podslurping, many things came to mind. My second reaction was along the lines of &quot;we&#039;ve known about the risk from USB and portable devices for a while, so what&#039;s new?&quot; Then I finally got around to reading the article and lear...</itunes:subtitle>
		<itunes:summary>When I first read the term podslurping, many things came to mind. My second reaction was along the lines of &quot;we&#039;ve known about the risk from USB and portable devices for a while, so what&#039;s new?&quot; Then I finally got around to reading the article and learning from Abe Usher why I needed a different mindset.

It turns out that advancements in USB technology, combined with the improvement of the devices that use USB and the ever-growing storage capacity, in fact, pose a significant potential threat. We focus a lot of time and energy right now on perimeter protections and the like - and yet freely recognize insider threats are more damaging.

Abe Usher got the word out, and now he joins Security Catalyst to help change the way we think about end point security. Listen now to learn how podslurping can affect you - and what you can do about it today.



Learn more about podslurping from Abe Usher at his Sharp Ideas website.

Continue the discussion and learn more about the technologies mentioned in the podcast in the Security Catalyst Forums (click here).

The &quot;Hot Topic&quot; of the week is Certs, Degrees, And Stuff, The Professionalizing of the IT Industry -- join in the conversation!
Join us next week for an insightful interview with Randal Schwartz!!</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 24 &#8211; (Insider Interviews) Wireless Security Basics with Red Wagner</title>
		<link>http://www.securitycatalyst.com/security-catalyst-24-insider-interviews-wireless-security-basics-with-red-wagner/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-24-insider-interviews-wireless-security-basics-with-red-wagner/#comments</comments>
		<pubDate>Fri, 07 Apr 2006 17:26:50 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=89</guid>
		<description><![CDATA[On this episode of the Security Catalyst, we are joined by Red Wagner who shares his research on wireless security basics, and the critical steps home and business users need to take to protect themselves. Listen in to learn the 5 steps you can take today to ensure you are more protected at home! I [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-24-insider-interviews-wireless-security-basics-with-red-wagner%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-24-insider-interviews-wireless-security-basics-with-red-wagner%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>On this episode of the Security Catalyst, we are joined by Red Wagner who shares his research on wireless<img align="right" alt="man holding monitor 2.gif" id="image105" title="man holding monitor 2.gif" src="http://www.securitycatalyst.com/wp-content/uploads/2006/04/man%20holding%20monitor%202.thumbnail.gif" /> security basics, and the critical steps home and business users need to take to protect themselves. Listen in to learn the 5 steps you can take today to ensure you are more protected at home!</p>
<p>I have been working on a Wireless Security &#8220;Basics&#8221; eGuide that Red has agreed to help with &#8211; and we should have that published by next week for your review and use.</p>
<p>Talk about wireless security in the forums here: <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=341">SC24 in the Catalyst Forums</a><br />
Red&#8217;s posted question in the forums is here, please answer it if you can: <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=337">Red Wagner&#8217;s Question &#8211; Gmail Chat  Security/privacy, Opt-out chat logging</a></p>
<p>Thanks for listening. If you liked the program, please tell a friend. If not, please tell me: &#115;e&#99;&#117;r&#105;ty&#99;a&#116;a&#108;&#121;st&#64;&#103;mai&#108;&#46;c&#111;&#109;
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-24-insider-interviews-wireless-security-basics-with-red-wagner%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-24-insider-interviews-wireless-security-basics-with-red-wagner%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-24-insider-interviews-wireless-security-basics-with-red-wagner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-24-20060407.mp3" length="16353987" type="audio/mpeg" />
			<itunes:keywords>Family Security,Information Protection,Podcast</itunes:keywords>
		<itunes:subtitle>On this episode of the Security Catalyst, we are joined by Red Wagner who shares his research on wireless security basics, and the critical steps home and business users need to take to protect themselves. Listen in to learn the 5 steps you can take to...</itunes:subtitle>
		<itunes:summary>On this episode of the Security Catalyst, we are joined by Red Wagner who shares his research on wireless security basics, and the critical steps home and business users need to take to protect themselves. Listen in to learn the 5 steps you can take today to ensure you are more protected at home!

I have been working on a Wireless Security &quot;Basics&quot; eGuide that Red has agreed to help with - and we should have that published by next week for your review and use.

Talk about wireless security in the forums here: SC24 in the Catalyst Forums
Red&#039;s posted question in the forums is here, please answer it if you can: Red Wagner&#039;s Question - Gmail Chat  Security/privacy, Opt-out chat logging

Thanks for listening. If you liked the program, please tell a friend. If not, please tell me: securitycatalyst@gmail.com</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 23 &#8211; Greylisting (and why you should be using it)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-23-greylisting-and-why-you-should-be-using-it/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-23-greylisting-and-why-you-should-be-using-it/#comments</comments>
		<pubDate>Wed, 05 Apr 2006 21:06:57 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=84</guid>
		<description><![CDATA[Join me as we start our look at open source email protections by looking at Greylisting. Greylisting is a simple, but highly effective, measure to help reduce spam. What is most promising about greylisting is that it actually provides a great economic disincentive to spammers at a low economic cost for us. OUTSTANDING! So listen [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-23-greylisting-and-why-you-should-be-using-it%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-23-greylisting-and-why-you-should-be-using-it%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><img align="right" alt="Cow Mailbox" id="image95" title="Cow Mailbox" src="http://www.securitycatalyst.com/wp-content/uploads/2006/04/cow%20mailbox%203.thumbnail.gif" /></p>
<p>Join me as we start our look at open source email protections by looking at Greylisting. Greylisting is a simple, but highly effective, measure to help reduce spam. What is most promising about greylisting is that it actually provides a great economic disincentive to spammers at a low economic cost for us. OUTSTANDING!</p>
<p>So listen in and learn how you can use greylisting to your benefit and join me in providing cost effective ways to reduce spam.</p>
<p>If you would like to join the Security Catalyst Research effort to implement greylisting, please go to the forums here: <a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=334">Forum Topic (This does require FREE registration)</a><br />
If you would like to learn more about greylisting, <a target="_blank" href="http://projects.puremagic.com/greylisting/whitepaper.html">click here to read the whitepaper written by Evan Harris.</a></p>
<p>The forum question of the week, needing YOUR answer is here:  <span id="tid-span-329" /><a title="This topic was started: Mar 27 2006, 11:53 AM. Click and hold to edit title" id="tid-link-329" target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=329">Looking To Get Certified</a></p>
<p>Thanks for listening! If you liked the podcast, please tell a friend. If not, or you have suggestions for how to improve, please tell me: &#115;&#101;c&#117;&#114;&#105;&#116;y&#99;at&#97;ly&#115;&#116;&#64;&#103;ma&#105;l&#46;&#99;o&#109;.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-23-greylisting-and-why-you-should-be-using-it%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-23-greylisting-and-why-you-should-be-using-it%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-23-greylisting-and-why-you-should-be-using-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-23-20060405.mp3" length="16056368" type="audio/mpeg" />
			<itunes:keywords>Podcast</itunes:keywords>
		<itunes:subtitle>  Join me as we start our look at open source email protections by looking at Greylisting. Greylisting is a simple, but highly effective, measure to help reduce spam. What is most promising about greylisting is that it actually provides a great economi...</itunes:subtitle>
		<itunes:summary>

Join me as we start our look at open source email protections by looking at Greylisting. Greylisting is a simple, but highly effective, measure to help reduce spam. What is most promising about greylisting is that it actually provides a great economic disincentive to spammers at a low economic cost for us. OUTSTANDING!

So listen in and learn how you can use greylisting to your benefit and join me in providing cost effective ways to reduce spam.

If you would like to join the Security Catalyst Research effort to implement greylisting, please go to the forums here: Forum Topic (This does require FREE registration)
If you would like to learn more about greylisting, click here to read the whitepaper written by Evan Harris.

The forum question of the week, needing YOUR answer is here:  Looking To Get Certified

Thanks for listening! If you liked the podcast, please tell a friend. If not, or you have suggestions for how to improve, please tell me: securitycatalyst@gmail.com.</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 22 (Insider Interviews) &#8211; How to protect yourself from Identity Theft with John Sileo</title>
		<link>http://www.securitycatalyst.com/security-catalyst-22-insider-interviews-how-to-protect-yourself-from-identity-theft-with-john-sileo/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-22-insider-interviews-how-to-protect-yourself-from-identity-theft-with-john-sileo/#comments</comments>
		<pubDate>Fri, 31 Mar 2006 04:15:42 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=80</guid>
		<description><![CDATA[Identity Theft is a topic covered nearly every day in the newspapers, magazines and television programs we watch. It continues to be the top complaint filed with the FTC each year &#8212; and as this problem continues to grow, we suddenly have a lot of &#8220;experts&#8221; handing out misleading and wrong information!! Do you know [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-22-insider-interviews-how-to-protect-yourself-from-identity-theft-with-john-sileo%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-22-insider-interviews-how-to-protect-yourself-from-identity-theft-with-john-sileo%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Identity Theft is a topic covered nearly every day in the newspapers, magazines and television programs we watch. It continues to be the top complaint filed with the FTC each year &#8212; and as this problem continues to grow, we suddenly have a lot of &#8220;experts&#8221; handing out misleading and wrong information!! Do you know what to do to protect yourself? Are you sure?<br />
For our Security Insider Interview this week, we are joined by Identity Theft expert and author of Stolen Lives, John Sileo. John and I met this summer at the National Speakers Association, and I was skeptical at first about his expertise (since like I already wrote, there are a lot of people who claim to be experts). I&#8217;m happy to tell you that John is the real deal &#8211; and you&#8217;ll learn why and experience his passion in our interview.</p>
<p>This is a show you will want to listen to again and share with your friends. <strong>IF YOU DO NOTHING ELSE, PLEASE TAKE SOME ACTION TO PROTECT YOURSELF TODAY</strong>. John offers sound advice; if you follow his suggestions, you just might prevent your own personal disaster.</p>
<p>***</p>
<p><a target="_blank" href="http://forums.securitycatalyst.com/index.php?showtopic=330">Continue the conversation in the FREE security catalyst forums by clicking here</a></p>
<p>***</p>
<p>To learn how to <em>&#8220;think like a spy,&#8221;</em> use this link to order the <a href="http://www.1shoppingcart.com/app/?Clk=1357011"> Stolen Lives Book.<img width="60" height="96" id="image92" alt="Stolen Lives" src="http://www.securitycatalyst.com/wp-content/uploads/2006/03/stolenlivescover-sm-101305.thumbnail.jpg" /></a></p>
<p>You can reach John Sileo by visiting his website at:  <a target="_blank" href="http://www.thinklikeaspy.com/">http://www.thinklikeaspy.com/</a></p>
<p><em>Please take a moment to rate the show in Yahoo! Podcasts with the links to the right. If you liked the show, please tell a friend. If not, please tell me: &#115;&#101;&#99;u&#114;&#105;t&#121;&#99;at&#97;&#108;y&#115;&#116;&#64;&#103;&#109;&#97;i&#108;.com.</em>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-22-insider-interviews-how-to-protect-yourself-from-identity-theft-with-john-sileo%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-22-insider-interviews-how-to-protect-yourself-from-identity-theft-with-john-sileo%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-22-insider-interviews-how-to-protect-yourself-from-identity-theft-with-john-sileo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-22-20060330.mp3" length="19424513" type="audio/mpeg" />
			<itunes:keywords>Information Protection,Podcast</itunes:keywords>
		<itunes:subtitle>Identity Theft is a topic covered nearly every day in the newspapers, magazines and television programs we watch. It continues to be the top complaint filed with the FTC each year -- and as this problem continues to grow,</itunes:subtitle>
		<itunes:summary>Identity Theft is a topic covered nearly every day in the newspapers, magazines and television programs we watch. It continues to be the top complaint filed with the FTC each year -- and as this problem continues to grow, we suddenly have a lot of &quot;experts&quot; handing out misleading and wrong information!! Do you know what to do to protect yourself? Are you sure?
For our Security Insider Interview this week, we are joined by Identity Theft expert and author of Stolen Lives, John Sileo. John and I met this summer at the National Speakers Association, and I was skeptical at first about his expertise (since like I already wrote, there are a lot of people who claim to be experts). I&#039;m happy to tell you that John is the real deal - and you&#039;ll learn why and experience his passion in our interview.

This is a show you will want to listen to again and share with your friends. IF YOU DO NOTHING ELSE, PLEASE TAKE SOME ACTION TO PROTECT YOURSELF TODAY. John offers sound advice; if you follow his suggestions, you just might prevent your own personal disaster.

***

Continue the conversation in the FREE security catalyst forums by clicking here

***

To learn how to &quot;think like a spy,&quot; use this link to order the  Stolen Lives Book.

You can reach John Sileo by visiting his website at:  http://www.thinklikeaspy.com/

Please take a moment to rate the show in Yahoo! Podcasts with the links to the right. If you liked the show, please tell a friend. If not, please tell me: securitycatalyst@gmail.com.</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 20 &#8211; Email Security with Matt Yoder</title>
		<link>http://www.securitycatalyst.com/security-catalyst-20-email-security-with-matt-yoder/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-20-email-security-with-matt-yoder/#comments</comments>
		<pubDate>Mon, 13 Mar 2006 04:22:36 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=70</guid>
		<description><![CDATA[Back from Vegas, Matt Yoder shares his insights on email security. This candid interview includes some basic information, as well as the considerations every company should be taking into account when dealing with compliance and email security.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-20-email-security-with-matt-yoder%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-20-email-security-with-matt-yoder%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Back from Vegas, Matt Yoder shares his insights on email security. This candid interview includes some basic information, as well as the considerations every company should be taking into account when dealing with compliance and email security.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-20-email-security-with-matt-yoder%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-20-email-security-with-matt-yoder%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-20-email-security-with-matt-yoder/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-20-20060309.mp3" length="13665238" type="audio/mpeg" />
			<itunes:keywords>Podcast</itunes:keywords>
		<itunes:subtitle>Back from Vegas, Matt Yoder shares his insights on email security. This candid interview includes some basic information, as well as the considerations every company should be taking into account when dealing with compliance and email security.</itunes:subtitle>
		<itunes:summary>Back from Vegas, Matt Yoder shares his insights on email security. This candid interview includes some basic information, as well as the considerations every company should be taking into account when dealing with compliance and email security.</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 19 &#8211; The Secrets of Risk Management (With Ron Woerner)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-19-the-secrets-of-risk-management-with-ron-woerner/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-19-the-secrets-of-risk-management-with-ron-woerner/#comments</comments>
		<pubDate>Wed, 22 Feb 2006 06:29:37 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=67</guid>
		<description><![CDATA[I had the opportunity yesterday to speak with Ron Woerner about Risk Management&#8230; and I was so impressed and excited about the tips and advice that he shared that I decided to get this out to you right away. Ron Woerner is an expert in information security and has spearheaded an effort to develop an [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-19-the-secrets-of-risk-management-with-ron-woerner%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-19-the-secrets-of-risk-management-with-ron-woerner%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I had the opportunity yesterday to speak with Ron Woerner about Risk Management&#8230; and I was so impressed and excited about the tips and advice that he shared that I decided to get this out to you right away.</p>
<p>Ron Woerner is an expert in information security and has spearheaded an effort to develop an effective risk management program for a large company. He agreed to speak with me about his experiences &#8211; and provides great ideas, insights and information that we can all use!</p>
<p>I want to thank Ron for speaking with us and for sending along some resources. I’ve actually invited Ron to present on “FREE SECURITY” in an upcoming free teleseminar for our newsletter subscribers. Subscribe today so you don’t miss the resources he is going to share.</p>
<p>If you enjoyed this interview, please tell a friend, colleague or other security professional &#8212; this is an important topic, and the 25 minutes Ron shared will help anyone save a lot of time and money!</p>
<p><strong> Risk Management Resources</strong></p>
<p><span id="more-67"></span></p>
<p><a target="_blank" href="http://www.asisonline.org/guidelines/guidelinesgsra.pdf">ASIS International, General Security Risk Assessment Guideline, 2003 </a></p>
<p><a target="_blank" href="http://www.bitsinfo.org/bitskalculatorjuly04.pdf">BITS, Kalculator: Key Risk Measurement Tool for Information Security Operational Risks, July 2004</a><br />
<a target="_blank" href="http://www.cio.com/archive/110104/risk.html" /></p>
<p><a target="_blank" href="http://www.cio.com/archive/110104/risk.html">Berinato, Scott, “Enterprise Risk Management,” CIO Magazine, November 1, 2004, pp. 46-58 </a></p>
<p>Bernstein, Peter L., Against the Gods: The Remarkable Story of Risk, John Wiley &#038; Sons, 1998.<br />
<a target="_blank" href="http://www.coso.org/" /></p>
<p><a target="_blank" href="http://www.coso.org/">COSO (Committee of Sponsoring Organizations of the Treadway Commission), Enterprise Risk Management – Integrated Framework, September 2004</a><br />
<a target="_blank" href="http://www.theirm.org/publications/documents/Risk_Management_Standard_030820.pdf" /></p>
<p><a target="_blank" href="http://www.theirm.org/publications/documents/Risk_Management_Standard_030820.pdf">IRM AIRMIC &#038; ALARM, A Risk Management Standard, 2002</a><br />
<a target="_blank" href="http://www.microsoft.com/technet/security/guidance/secrisk/default.mspx" /></p>
<p><a target="_blank" href="http://www.microsoft.com/technet/security/guidance/secrisk/default.mspx">Microsoft Corporation, The Security Risk Management Guide, 2004</a></p>
<p><a target="_blank" href="http://www.csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf"> NIST (National Institute of Standards and Technology), Special Publication 800-30: Risk Management Guide for Information Technology Systems, October 2001.</a></p>
<p><a target="_blank" href="http://www.csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf" /><br />
<a target="_blank" href="http://www.csrc.nist.gov/publications/nistpubs/800-37/SP800-37-final.pdf"> NIST (National Institute of Standards and Technology), Special Publication 800-37: Guide for Security Certification and Accreditation of Federal Information Systems, May 2004.<br />
</a></p>
<p><a target="_blank" href="http://www.csrc.nist.gov/publications/nistpubs/800-64/NIST-SP800-64.pdf"> NIST (National Institute of Standards and Technology), Special Publication 800-64: Security Considerations in the Information System Development Life Cycle, October 2003.</a><br />
<a target="_blank" href="http://www.sei.cmu.edu/risk/risk.faq.html" /></p>
<p><a target="_blank" href="http://www.sei.cmu.edu/risk/risk.faq.html">Risk Management FAQ, Carnegie-Mellon Software Engineering Institute</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-19-the-secrets-of-risk-management-with-ron-woerner%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-19-the-secrets-of-risk-management-with-ron-woerner%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-19-the-secrets-of-risk-management-with-ron-woerner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-19-20060221.mp3" length="15817130" type="audio/mpeg" />
			<itunes:keywords>Information Protection,Podcast</itunes:keywords>
		<itunes:subtitle>I had the opportunity yesterday to speak with Ron Woerner about Risk Management... and I was so impressed and excited about the tips and advice that he shared that I decided to get this out to you right away.</itunes:subtitle>
		<itunes:summary>I had the opportunity yesterday to speak with Ron Woerner about Risk Management... and I was so impressed and excited about the tips and advice that he shared that I decided to get this out to you right away.

Ron Woerner is an expert in information security and has spearheaded an effort to develop an effective risk management program for a large company. He agreed to speak with me about his experiences - and provides great ideas, insights and information that we can all use!

I want to thank Ron for speaking with us and for sending along some resources. Iâve actually invited Ron to present on âFREE SECURITYâ in an upcoming free teleseminar for our newsletter subscribers. Subscribe today so you donât miss the resources he is going to share.

If you enjoyed this interview, please tell a friend, colleague or other security professional -- this is an important topic, and the 25 minutes Ron shared will help anyone save a lot of time and money!

 Risk Management Resources



ASIS International, General Security Risk Assessment Guideline, 2003 

BITS, Kalculator: Key Risk Measurement Tool for Information Security Operational Risks, July 2004


Berinato, Scott, âEnterprise Risk Management,â CIO Magazine, November 1, 2004, pp. 46-58 

Bernstein, Peter L., Against the Gods: The Remarkable Story of Risk, John Wiley &amp; Sons, 1998.


COSO (Committee of Sponsoring Organizations of the Treadway Commission), Enterprise Risk Management â Integrated Framework, September 2004


IRM AIRMIC &amp; ALARM, A Risk Management Standard, 2002


Microsoft Corporation, The Security Risk Management Guide, 2004

 NIST (National Institute of Standards and Technology), Special Publication 800-30: Risk Management Guide for Information Technology Systems, October 2001.


 NIST (National Institute of Standards and Technology), Special Publication 800-37: Guide for Security Certification and Accreditation of Federal Information Systems, May 2004.


 NIST (National Institute of Standards and Technology), Special Publication 800-64: Security Considerations in the Information System Development Life Cycle, October 2003.


Risk Management FAQ, Carnegie-Mellon Software Engineering Institute</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 18 (In the Trenches Interview with FBI Special Agent Jim Beane)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-18-in-the-trenches-cyber-and-homeland-security-interview-with-fbi/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-18-in-the-trenches-cyber-and-homeland-security-interview-with-fbi/#comments</comments>
		<pubDate>Fri, 17 Feb 2006 07:03:37 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=64</guid>
		<description><![CDATA[I am pleased to offer you Security Catalyst 18, an &#8220;In the trenches&#8221; edition that focuses on Cyber and Homeland Security. The current belief is that 85% or more of our critical infrastructure that needs to be protected is owned and operated by the private sector. So how do we effectively share information with the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-18-in-the-trenches-cyber-and-homeland-security-interview-with-fbi%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-18-in-the-trenches-cyber-and-homeland-security-interview-with-fbi%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I am pleased to offer you Security Catalyst 18, an &#8220;In the trenches&#8221; edition that focuses on Cyber and Homeland Security. The current belief is that 85% or more of our critical infrastructure that needs to be protected is owned and operated by the private sector. So how do we effectively share information with the government and what should we be doing to protect ourselves? <strong><em>This show is geared for anyone interested in Homeland Security &#8211; especially if you want to make a difference.<br />
</em></strong><br />
One program available to US citizens and companies is Infragard &#8211; the joint partnership between the FBI and corporations to foster that cooperation. I recently was able to interview Special Agent Jim Beane, from the Albany, NY Division about his experience in the FBI as it related to cybercrime, homeland security and InfraGard.</p>
<p>Special Agent Beane candidly shares some insights about the value of sharing information, as well as dispells some myths and provides important information on how we can better help in the effort to secure cyberspace and protect our homeland.</p>
<p><em>If you have questions about membership in</em><em> InfraGard or cybercrime that were not addressed, please send me an email to <strong>se&#99;&#117;ri&#116;ycatal&#121;&#115;t&#64;&#103;&#109;ail.com</strong> and I will work to get them answered for you.<br />
</em></p>
<p>Links and Information</p>
<p><span id="more-64"></span></p>
<p>Please remember to rate this podcast on iTunes and Yahoo! Thanks!!</p>
<p>Here are some notes and links from this episode</p>
<p><a target="_blank" href="http://www.infragard.net/">InfraGard &#8211; Guarding the Nation&#8217;s Infrastructure</a></p>
<p><a target="_blank" href="http://www.infragard.net/membership/index.htm">To Join InfraGard</a></p>
<p><a target="_blank" href="http://www.ic3.gov/">To report an cyber-related complaint &#8212; Internet Crime Complaint Center</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-18-in-the-trenches-cyber-and-homeland-security-interview-with-fbi%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-18-in-the-trenches-cyber-and-homeland-security-interview-with-fbi%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-18-in-the-trenches-cyber-and-homeland-security-interview-with-fbi/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-18-20060216.mp3" length="10022117" type="audio/mpeg" />
			<itunes:keywords>Information Protection,Podcast</itunes:keywords>
		<itunes:subtitle>I am pleased to offer you Security Catalyst 18, an &quot;In the trenches&quot; edition that focuses on Cyber and Homeland Security. The current belief is that 85% or more of our critical infrastructure that needs to be protected is owned and operated by the priv...</itunes:subtitle>
		<itunes:summary>I am pleased to offer you Security Catalyst 18, an &quot;In the trenches&quot; edition that focuses on Cyber and Homeland Security. The current belief is that 85% or more of our critical infrastructure that needs to be protected is owned and operated by the private sector. So how do we effectively share information with the government and what should we be doing to protect ourselves? This show is geared for anyone interested in Homeland Security - especially if you want to make a difference.

One program available to US citizens and companies is Infragard - the joint partnership between the FBI and corporations to foster that cooperation. I recently was able to interview Special Agent Jim Beane, from the Albany, NY Division about his experience in the FBI as it related to cybercrime, homeland security and InfraGard.

Special Agent Beane candidly shares some insights about the value of sharing information, as well as dispells some myths and provides important information on how we can better help in the effort to secure cyberspace and protect our homeland.

If you have questions about membership in InfraGard or cybercrime that were not addressed, please send me an email to securitycatalyst@gmail.com and I will work to get them answered for you.


Links and Information



Please remember to rate this podcast on iTunes and Yahoo! Thanks!!

Here are some notes and links from this episode

InfraGard - Guarding the Nation&#039;s Infrastructure

To Join InfraGard

To report an cyber-related complaint -- Internet Crime Complaint Center</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 17 (Home User Security &#8211; Email and Browsers)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-17-home-user-security-email-and-browsers/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-17-home-user-security-email-and-browsers/#comments</comments>
		<pubDate>Mon, 13 Feb 2006 20:20:39 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=61</guid>
		<description><![CDATA[This is our second special episode focusing on Home User security issues. Today we focus on email clients and browsers &#8211; and the basic steps you need to take to protect yourself. Michael is joined by special guest Bill Matherly, Jr. &#8211; and they describe the actions they take to protect themselves, and their friends [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-17-home-user-security-email-and-browsers%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-17-home-user-security-email-and-browsers%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>This is our second special episode focusing on Home User security issues. Today we focus on email clients and browsers &#8211; and the basic steps you need to take to protect yourself. Michael is joined by special guest Bill Matherly, Jr. &#8211; and they describe the actions they take to protect themselves, and their friends and family.</p>
<p>Listen to the show to see which programs and configurations we recomend to our family and friends. As our new friends, you&#8217;ll want to make use of our links and information to keep yourself protected!</p>
<p>Links and Information</p>
<p><span id="more-61"></span></p>
<p>Please remember to rate this podcast on iTunes and Yahoo! Thanks!!</p>
<p>Here are some notes and links from the show today:</p>
<p><a target="_blank" href="http://www.mozilla.com/firefox/">Firefox</a></p>
<p><a target="_blank" href="http://www.mozilla.com/thunderbird/">Thunderbird</a></p>
<p><a target="_blank" href="http://www.securitycatalyst.com/?page_id=55">Security Catalyst Consumer/Home User Security Resources </a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-17-home-user-security-email-and-browsers%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-17-home-user-security-email-and-browsers%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-17-home-user-security-email-and-browsers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-17-20060213.mp3" length="16628966" type="audio/mpeg" />
			<itunes:keywords>Family Security,Podcast</itunes:keywords>
		<itunes:subtitle>This is our second special episode focusing on Home User security issues. Today we focus on email clients and browsers - and the basic steps you need to take to protect yourself. Michael is joined by special guest Bill Matherly, Jr.</itunes:subtitle>
		<itunes:summary>This is our second special episode focusing on Home User security issues. Today we focus on email clients and browsers - and the basic steps you need to take to protect yourself. Michael is joined by special guest Bill Matherly, Jr. - and they describe the actions they take to protect themselves, and their friends and family.

Listen to the show to see which programs and configurations we recomend to our family and friends. As our new friends, you&#039;ll want to make use of our links and information to keep yourself protected!

Links and Information



Please remember to rate this podcast on iTunes and Yahoo! Thanks!!

Here are some notes and links from the show today:

Firefox

Thunderbird

Security Catalyst Consumer/Home User Security Resources </itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 15 (Cell Phone Records, Anonym.OS, Biometrics at School)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-15-cell-phone-records-anonymos-biometrics-at-school/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-15-cell-phone-records-anonymos-biometrics-at-school/#comments</comments>
		<pubDate>Sat, 28 Jan 2006 22:22:15 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=54</guid>
		<description><![CDATA[After a hectic travel week, we present Security Catalyst 15. Join Michael as he examines the issues around cell phone numbers and records being offered for sale, a newly announced anonym.OS operating system and the how a NJ school is using biometrics &#8212; and 4 questions you need to ask if your organization is thinking [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-15-cell-phone-records-anonymos-biometrics-at-school%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-15-cell-phone-records-anonymos-biometrics-at-school%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>After a hectic travel week, we present Security Catalyst 15. Join Michael as he examines the issues around cell phone numbers and records being offered for sale, a newly announced anonym.OS operating system and the how a NJ school is using biometrics &#8212; and 4 questions you need to ask if your organization is thinking about using biometrics.</p>
<p><span id="more-54"></span><br />
Here are some notes and links from the show today:</p>
<p><a href="http://www.ftc.gov/opa/2006/01/dnccellphones.htm">The Official FTC Advisory on Cell Phone Telephone Numbers</a></p>
<p><a href="http://tor.eff.org/">Tor: An anonymous Internet communication system</a></p>
<p><a href="http://theory.kaos.to/projects.html">Anonym.OS LiveCD</a></p>
<p><a href="http://www.eyemetric.com/">eyemetric identity systems</a></p>
<p><a href="http://www.ibia.org/">The International Biometric Industry Association (IBIA)</a></p>
<p><a href="http://www.ibia.org/membersadmin/whitepapers/pdf/14/irisrecog.pdf">How Iris Recognition Works</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-15-cell-phone-records-anonymos-biometrics-at-school%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-15-cell-phone-records-anonymos-biometrics-at-school%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-15-cell-phone-records-anonymos-biometrics-at-school/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-15-20060128.mp3" length="5778494" type="audio/mpeg" />
			<itunes:keywords>Information Protection,Podcast</itunes:keywords>
		<itunes:subtitle>After a hectic travel week, we present Security Catalyst 15. Join Michael as he examines the issues around cell phone numbers and records being offered for sale, a newly announced anonym.OS operating system and the how a NJ school is using biometrics -...</itunes:subtitle>
		<itunes:summary>After a hectic travel week, we present Security Catalyst 15. Join Michael as he examines the issues around cell phone numbers and records being offered for sale, a newly announced anonym.OS operating system and the how a NJ school is using biometrics -- and 4 questions you need to ask if your organization is thinking about using biometrics.


Here are some notes and links from the show today:

The Official FTC Advisory on Cell Phone Telephone Numbers

Tor: An anonymous Internet communication system

Anonym.OS LiveCD

eyemetric identity systems

The International Biometric Industry Association (IBIA)

How Iris Recognition Works</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 14 (Rundown with Matt Yoder #1)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-14-rundown-with-matt-yoder-1/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-14-rundown-with-matt-yoder-1/#comments</comments>
		<pubDate>Mon, 23 Jan 2006 03:06:25 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=49</guid>
		<description><![CDATA[Join us as Matt Yoder, formerly just a text contributor to the blog, finally puts his money where his mouth is (or vice versa,) and joins Michael in co-hosting the Security Catalyst Rundown #1! On this episode, we dive into the industry lingo and what is really meant by &#8220;rootkit, trojan, and backdoor,&#8221; and how [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-14-rundown-with-matt-yoder-1%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-14-rundown-with-matt-yoder-1%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Join us as Matt Yoder, formerly just a text contributor to the blog, finally puts his money where his mouth is (or vice versa,) and joins Michael in co-hosting the Security Catalyst Rundown #1!</p>
<p>On this episode, we dive into the industry lingo and what is really meant by &#8220;rootkit, trojan, and backdoor,&#8221; and how those terms relate to some of the topics in the news lately.  We also discuss patch management for a home user as it compares to the corporate world, and analyze some of the difficulties both sides get to contend with.  We then wrap up with an introductory look at Risk Assessment, and are reminded that NIST has recently updated their excellent guidance document, SP800-40 with a second version (November 2005).</p>
<p>The links from the show are here….<br />
<a href="http://csrc.nist.gov/publications/nistpubs/800-40-Ver2/SP800-40v2.pdf">Creating a Patch and Vulnerability Management Program (NIST SP 800-40V2)<br />
</a></p>
<p><em>We developed this weekend show based on feedback and a desire to introduce some new ideas into the security dialogue.  Send feedback, ideas, suggestions and questions to se&#99;&#117;ri&#116;&#121;cata&#108;&#121;&#115;&#116;&#64;g&#109;a&#105;l&#46;&#99;&#111;&#109;. Thanks for listening!</em></p>
<p>The following track from the podsafe music collection of podshow was used during the introduction of SC14.<br />
BAJA TAXI</p>
<p>Please remember to rate this podcast on iTunes and Yahoo! Thanks!!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-14-rundown-with-matt-yoder-1%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-14-rundown-with-matt-yoder-1%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-14-rundown-with-matt-yoder-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-14-20060122.mp3" length="16410392" type="audio/mpeg" />
			<itunes:keywords>Podcast</itunes:keywords>
		<itunes:subtitle>Join us as Matt Yoder, formerly just a text contributor to the blog, finally puts his money where his mouth is (or vice versa,) and joins Michael in co-hosting the Security Catalyst Rundown #1!  On this episode,</itunes:subtitle>
		<itunes:summary>Join us as Matt Yoder, formerly just a text contributor to the blog, finally puts his money where his mouth is (or vice versa,) and joins Michael in co-hosting the Security Catalyst Rundown #1!

On this episode, we dive into the industry lingo and what is really meant by &quot;rootkit, trojan, and backdoor,&quot; and how those terms relate to some of the topics in the news lately.  We also discuss patch management for a home user as it compares to the corporate world, and analyze some of the difficulties both sides get to contend with.  We then wrap up with an introductory look at Risk Assessment, and are reminded that NIST has recently updated their excellent guidance document, SP800-40 with a second version (November 2005).

The links from the show are hereâ¦.
Creating a Patch and Vulnerability Management Program (NIST SP 800-40V2)


We developed this weekend show based on feedback and a desire to introduce some new ideas into the security dialogue.  Send feedback, ideas, suggestions and questions to securitycatalyst@gmail.com. Thanks for listening!

The following track from the podsafe music collection of podshow was used during the introduction of SC14.
BAJA TAXI

Please remember to rate this podcast on iTunes and Yahoo! Thanks!!</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 13 (Home User Security Basics)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-13-home-user-security-basics/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-13-home-user-security-basics/#comments</comments>
		<pubDate>Fri, 20 Jan 2006 14:17:35 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=47</guid>
		<description><![CDATA[Join us as Michael interviews Bill, a former &#8220;black hat&#8221; hacker (reformed) about the 3 basic steps we advise our friends and familes to take when it comes to protecting their home computers. While there are many things you can do to protect yourself and your family when connecting a computer to the Internet, we [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-13-home-user-security-basics%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-13-home-user-security-basics%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Join us as Michael interviews Bill, a former &#8220;black hat&#8221; hacker (reformed) about the 3 basic steps we advise our friends and familes to take when it comes to protecting their home computers. While there are many things you can do to protect yourself and your family when connecting a computer to the Internet, we cover the three things you absolutely <em>must</em> do!</p>
<p>Join us as we discuss why these steps are important and gain the knowledge you need to be a bit safer!</p>
<p>The links from the show are here&#8230;.<br />
We are in the process of building a collection of consumer/home computer security links. <a href="http://www.securitycatalyst.com/?page_id=55">Click here to check the current list and get information about updating your system, firewalls, anti-virus, anti-spyware and some good general advice.</a></p>
<p>The following track from the podsafe music collection of podshow was used during the introduction of SC13.<br />
<a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=51bfa21542a4ed74fd85ca6decd1612d">BAJA TAXI</a></p>
<p>Please remember to rate this podcast on iTunes and Yahoo! Thanks!!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-13-home-user-security-basics%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-13-home-user-security-basics%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-13-home-user-security-basics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-13-20060119.mp3" length="16037247" type="audio/mpeg" />
			<itunes:keywords>Family Security,Podcast</itunes:keywords>
		<itunes:subtitle>Join us as Michael interviews Bill, a former &quot;black hat&quot; hacker (reformed) about the 3 basic steps we advise our friends and familes to take when it comes to protecting their home computers. While there are many things you can do to protect yourself an...</itunes:subtitle>
		<itunes:summary>Join us as Michael interviews Bill, a former &quot;black hat&quot; hacker (reformed) about the 3 basic steps we advise our friends and familes to take when it comes to protecting their home computers. While there are many things you can do to protect yourself and your family when connecting a computer to the Internet, we cover the three things you absolutely must do!

Join us as we discuss why these steps are important and gain the knowledge you need to be a bit safer!

The links from the show are here....
We are in the process of building a collection of consumer/home computer security links. Click here to check the current list and get information about updating your system, firewalls, anti-virus, anti-spyware and some good general advice.

The following track from the podsafe music collection of podshow was used during the introduction of SC13.
BAJA TAXI

Please remember to rate this podcast on iTunes and Yahoo! Thanks!!</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 12 (Symantec Rootkit, More Microsoft, Military Accounts)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-12-symantec-rootkit-more-microsoft-military-accounts/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-12-symantec-rootkit-more-microsoft-military-accounts/#comments</comments>
		<pubDate>Sun, 15 Jan 2006 18:27:48 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=45</guid>
		<description><![CDATA[The recent Symantec vulnerability that affects 63 (!) of it&#8217;s products was announced in the end of December, but flew under the radar. They were back in the news this week with discussions about a rootkit &#8212; and we examine both issues and help you take steps to be protected. We also briefly look at [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-12-symantec-rootkit-more-microsoft-military-accounts%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-12-symantec-rootkit-more-microsoft-military-accounts%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>The recent Symantec vulnerability that affects 63 (!) of it&#8217;s products was announced in the end of December, but flew under the radar. They were back in the news this week with discussions about a rootkit &#8212; and we examine both issues and help you take steps to be protected. We also briefly look at the new security concerns for exchange/outlook and then focus on talking about dormant user accounts and the large security risk they pose. We talk specifically about key actions you can take to reduce your risk.</p>
<p>The following track from the podsafe music collection of podshow was used during the introduction of SC12.<br />
<a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=51bfa21542a4ed74fd85ca6decd1612d">BAJA TAXI</a>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-12-symantec-rootkit-more-microsoft-military-accounts%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-12-symantec-rootkit-more-microsoft-military-accounts%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-12-symantec-rootkit-more-microsoft-military-accounts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-12-20060114.mp3" length="19405165" type="audio/mpeg" />
			<itunes:keywords>Podcast</itunes:keywords>
		<itunes:subtitle>The recent Symantec vulnerability that affects 63 (!) of it&#039;s products was announced in the end of December, but flew under the radar. They were back in the news this week with discussions about a rootkit -- and we examine both issues and help you take...</itunes:subtitle>
		<itunes:summary>The recent Symantec vulnerability that affects 63 (!) of it&#039;s products was announced in the end of December, but flew under the radar. They were back in the news this week with discussions about a rootkit -- and we examine both issues and help you take steps to be protected. We also briefly look at the new security concerns for exchange/outlook and then focus on talking about dormant user accounts and the large security risk they pose. We talk specifically about key actions you can take to reduce your risk.

The following track from the podsafe music collection of podshow was used during the introduction of SC12.
BAJA TAXI</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>Security Catalyst 11 &#8211; (WMF Patched, H&amp;R Block Blunder, DHS Takes a Stand)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-11-wmf-patched-hr-block-blunder-dhs-takes-a-stand/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-11-wmf-patched-hr-block-blunder-dhs-takes-a-stand/#comments</comments>
		<pubDate>Sat, 07 Jan 2006 17:50:42 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=42</guid>
		<description><![CDATA[Here is a list of things to do: * subscribe with the RSS 2.0 feed(s) to your right (or below for yahoo and iTunes) * Call the listener feedback line: 206-339-9361 * If you liked the show, tell a friend; if you didn&#8217;t, tell me! Subscribe in iTunes using this link (Click Here Now) Subscribe [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-11-wmf-patched-hr-block-blunder-dhs-takes-a-stand%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-11-wmf-patched-hr-block-blunder-dhs-takes-a-stand%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>Here is a list of things to do:</strong><br />
* subscribe with the RSS 2.0 feed(s) to your right (or below for yahoo and iTunes)<br />
* Call the listener feedback line: 206-339-9361<br />
* If you liked the show, tell a friend; if you didn&#8217;t, tell me! <!--email--></p>
<p><a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=95568073&#038;s=143441">Subscribe in iTunes using this link (Click Here Now)</a></p>
<p><a href="http://podcasts.yahoo.com/series?s=cf82adc909033628dfd68ead760680c2"><strong>Subscribe or RATE THE SHOW in Yahoo Here. Please take the time to rate the show for the series as well as the specific episode.</strong><br />
</a></p>
<p><strong><a href="http://www.securitycatalyst.com/podcasts/SC-11-20060107.mp3"> ==>Download or listen to Security Catalyst #11 here (27 minutes long) < ==</a></a></strong></p>
<p><strong>On This  Episode</strong><br />
<strong>The Windows WMF &#8220;Zero-Day Exploit&#8221; gets patched</strong><br />
<em>Well, the patch is out &#8211; several of them. We talk about the MS patch, as well as briefly touch on the discussion around third party patches, patch management and then focus on the larger issue of defense in depth. Are you practicing good defense in depth?</em></p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx">Microsoft Announcement and Information</a></p>
<p><strong>H&#038;R Block Blunder</strong><br />
<em>In reality, this isn&#8217;t probably going to be a big deal &#8211; but I was amazed as we ended the year to find yet <strong>another</strong> company has been required to notify customers that they may have had a compromise of personally identifiable information. In this case, the social security number (SSN) of the recipient of TaxCut software was included in the tracking number. We discuss corporate accountability and how to help protect your company from these mistakes.</em></p>
<p><a href="http://www.usatoday.com/money/perfi/taxes/2006-01-04-hr-block-privacy_x.htm">USA Today Story</a></p>
<p><strong>DHS takes a risk assessment approach</strong><br />
<em>Not enough attention has been positively applied to the common sense approach DHS is applying with homeland security money. Rather than dole out the money in a political fashion, they have decided to take a &#8220;risk-based&#8221; approach. While the specific details are only coming to light now, this is an excellent step that sets the example &#8211; and may give you the opportunity to take the same approach with your business or home network.</em></p>
<p><a href="http://www.dhs.gov/dhspublic/interapp/press_release/press_release_0824.xml">DHS Press Release</a></p>
<p>The following track from the podsafe music collection of podshow was used during the introduction of SC11.<br />
<a href="http://music.podshow.com/music/listeners/artistdetails.php?BandHash=51bfa21542a4ed74fd85ca6decd1612d">BAJA TAXI</a></p>
<p>Please remember to rate this podcast on iTunes and Yahoo! Thanks!!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-11-wmf-patched-hr-block-blunder-dhs-takes-a-stand%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-11-wmf-patched-hr-block-blunder-dhs-takes-a-stand%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-11-wmf-patched-hr-block-blunder-dhs-takes-a-stand/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-11-20060107.mp3" length="12949216" type="audio/mpeg" />
			<itunes:keywords>Podcast</itunes:keywords>
		<itunes:subtitle>Here is a list of things to do: * subscribe with the RSS 2.0 feed(s) to your right (or below for yahoo and iTunes) * Call the listener feedback line: 206-339-9361 * If you liked the show, tell a friend; if you didn&#039;t, tell me!</itunes:subtitle>
		<itunes:summary>Here is a list of things to do:
* subscribe with the RSS 2.0 feed(s) to your right (or below for yahoo and iTunes)
* Call the listener feedback line: 206-339-9361
* If you liked the show, tell a friend; if you didn&#039;t, tell me! 

Subscribe in iTunes using this link (Click Here Now)

Subscribe or RATE THE SHOW in Yahoo Here. Please take the time to rate the show for the series as well as the specific episode.


 ==&gt;Download or listen to Security Catalyst #11 here (27 minutes long) &lt; ==


On This  Episode
The Windows WMF &quot;Zero-Day Exploit&quot; gets patched
Well, the patch is out - several of them. We talk about the MS patch, as well as briefly touch on the discussion around third party patches, patch management and then focus on the larger issue of defense in depth. Are you practicing good defense in depth?

Microsoft Announcement and Information

H&amp;R Block Blunder
In reality, this isn&#039;t probably going to be a big deal - but I was amazed as we ended the year to find yet another company has been required to notify customers that they may have had a compromise of personally identifiable information. In this case, the social security number (SSN) of the recipient of TaxCut software was included in the tracking number. We discuss corporate accountability and how to help protect your company from these mistakes.

USA Today Story

DHS takes a risk assessment approach
Not enough attention has been positively applied to the common sense approach DHS is applying with homeland security money. Rather than dole out the money in a political fashion, they have decided to take a &quot;risk-based&quot; approach. While the specific details are only coming to light now, this is an excellent step that sets the example - and may give you the opportunity to take the same approach with your business or home network.

DHS Press Release


The following track from the podsafe music collection of podshow was used during the introduction of SC11.
BAJA TAXI

Please remember to rate this podcast on iTunes and Yahoo! Thanks!!</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
		<item>
		<title>WMF Exploit &#8211; letter to your users</title>
		<link>http://www.securitycatalyst.com/wmf-exploit-letter-to-your-users/</link>
		<comments>http://www.securitycatalyst.com/wmf-exploit-letter-to-your-users/#comments</comments>
		<pubDate>Mon, 02 Jan 2006 13:35:44 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Information Protection]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=38</guid>
		<description><![CDATA[Here is the message from Matt. Hopefully this saves you some time or otherwise helps out! Thanks, Matt, for taking the time to share! ====== Begin Message ======== A vulnerability with WMF (Windows Metafile) files was discovered on December 27, 2005. There are no patches for at this time to fix the problem (zero day [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fwmf-exploit-letter-to-your-users%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fwmf-exploit-letter-to-your-users%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Here is the message from Matt. Hopefully this saves you some time or otherwise helps out! Thanks, Matt, for taking the time to share!</p>
<p>====== Begin Message ========</p>
<p>A vulnerability with WMF (Windows Metafile) files was discovered on December 27, 2005.  There are no patches for at this time to fix the problem (zero day exploit).  Currently there are many websites in the wild that use the weakness in WMA to install Spyware on a user’s computer without the user‘s permission.  Even if you are using Firefox on a fully patched Windows XP SP2 system you are vulnerable.</p>
<p>A WMF file is an image file that supports both Vector and Bitmapped formats.  When a program opens a WMF multiple GDI calls are made to “draw” the image on the screen.  In older 16 bit versions of Windows there was a GDI call called SETABORTPROC that was used to execute code if there were any problems drawing the image.  This call still exists in current versions of Windows.</p>
<p>When you go to a website that takes advantage of the vulnerability it will send a corrupted WMF file to you.  When your computer draws the image it will fail, at that point it will execute the code from the SETABORTPROC section.  The code that executes can do pretty much anything that the currently logged on user can do.  (Install Spyware, virus, become a bot in an iRC chat etc..)</p>
<p>Alternatively the corrupt WMF file can cause buffer overflow errors as well using different GDI calls.</p>
<p>There really isn’t a fix for this.  There are some things you can do to help your self.</p>
<p>    * One is get ride of Google Desktop, it will launch (or relaunch) a virus or this vulnerability when it indexes a file.<br />
    * Unregistered the Windows Picture and Fax Viewer by click Start – Run and typing “regsvr32 -u %windir%\system32\shimgvw.dll”<br />
    * Enable DEP (Data Execution Prevention)<br />
    * Watch where you are going on the web…. (you know what I mean)<br />
    * Block Windows Metafile, although this can be tough since it can come in as something other then WMF.</p>
<p>Happy New Year</p>
<p>Matt Hull</p>
<p>====== end message =====
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fwmf-exploit-letter-to-your-users%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fwmf-exploit-letter-to-your-users%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/wmf-exploit-letter-to-your-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Catalyst #10 &#8211; (Windows WMF Exploit, SONY Settles, Year in Review)</title>
		<link>http://www.securitycatalyst.com/security-catalyst-10-windows-wmf-exploit-sony-settles-year-in-review/</link>
		<comments>http://www.securitycatalyst.com/security-catalyst-10-windows-wmf-exploit-sony-settles-year-in-review/#comments</comments>
		<pubDate>Fri, 30 Dec 2005 23:43:56 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=37</guid>
		<description><![CDATA[Here is a list of things to do: * subscribe with the RSS 2.0 feed(s) to your right * Call the listener feedback line: 206-339-9361 * If you liked the show, tell a friend; if you didn&#8217;t, tell me! Subscribe in iTunes using this link (Click Here Now) Subscribe or RATE THE SHOW in Yahoo [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-10-windows-wmf-exploit-sony-settles-year-in-review%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-10-windows-wmf-exploit-sony-settles-year-in-review%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>Here is a list of things to do:</strong><br />
* subscribe with the RSS 2.0 feed(s) to your right<br />
* Call the listener feedback line: 206-339-9361<br />
* If you liked the show, tell a friend; if you didn&#8217;t, tell me! <!--email--></p>
<p><a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=95568073&#038;s=143441">Subscribe in iTunes using this link (Click Here Now)</a></p>
<p><a href="http://podcasts.yahoo.com/series?s=cf82adc909033628dfd68ead760680c2"><strong>Subscribe or RATE THE SHOW in Yahoo Here. Please take the time to rate the show for the series as well as the specific episode.</strong><br />
</a></p>
<p><strong><a href="http://www.surveymonkey.com/s.asp?u=879171595986">Take the 2006 Security Spending Survey RIGHT NOW. DO IT.</a></strong></p>
<p><strong><a href="http://www.securitycatalyst.com/podcasts/SC-10-20051230.mp3"> ==>Download or listen to Security Catalyst #10 here (28 minutes long) < ==</a></a></strong></p>
<p><strong>On This  Episode</strong><br />
<strong>The Windows WMF &#8220;Zero-Day Exploit&#8221;</strong><br />
<em>We quickly explain the concepts behind &#8220;zero-day&#8221; attacks and exploits and the describe the current problem, as well as immediate steps you should take to protect yourself and your organization. </em></p>
<p>Here are some links with detailed information you can use to help protect yourself:<br />
<a href="http://www.f-secure.com/weblog/archives/archive-122005.html#00000755">F-Secure Weblog</a><br />
<a href="http://www.eweek.com/article2/0,1895,1906211,00.asp">Workaround, Protections Emerge for WMF Exploit</a><br />
<a href="http://www.microsoft.com/technet/security/advisory/912840.mspx">Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution &#8211; MICROSOFT</a><br />
<a href="http://www.kb.cert.org/vuls/id/181038">US-CERT: Vulnerability Note VU#181038</a></p>
<p><strong>The Proposed SONY-BMG Settlement</strong><br />
<em>The proposed settlement for CONSUMERS is interesting &#8211; and we take a look at the impact this may have to the long-term health of SONY-BMG, as well as what it may mean as a trend for corporate accountability.</em></p>
<p><strong>2005 in Review &#8211; and what to do with this knowledge!</strong><br />
<em>Rather than just recap some of the top trends, we go a bit deeper and look at what it means for those of us in the trenches &#8211; and what we might be doing about it next year. Even though some of the trends are negative, the results I found to be quite promising &#8212; especially as we look forward to an exciting and productive 2006.</em></p>
<p>Have a safe and Happy New Year!
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-10-windows-wmf-exploit-sony-settles-year-in-review%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsecurity-catalyst-10-windows-wmf-exploit-sony-settles-year-in-review%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/security-catalyst-10-windows-wmf-exploit-sony-settles-year-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.securitycatalyst.com/podcasts/SC-10-20051230.mp3" length="16514044" type="audio/mpeg" />
			<itunes:keywords>Podcast</itunes:keywords>
		<itunes:subtitle>Here is a list of things to do: * subscribe with the RSS 2.0 feed(s) to your right * Call the listener feedback line: 206-339-9361 * If you liked the show, tell a friend; if you didn&#039;t, tell me!   Subscribe in iTunes using this link (Click Here Now)  S...</itunes:subtitle>
		<itunes:summary>Here is a list of things to do:
* subscribe with the RSS 2.0 feed(s) to your right
* Call the listener feedback line: 206-339-9361
* If you liked the show, tell a friend; if you didn&#039;t, tell me! 

Subscribe in iTunes using this link (Click Here Now)

Subscribe or RATE THE SHOW in Yahoo Here. Please take the time to rate the show for the series as well as the specific episode.


Take the 2006 Security Spending Survey RIGHT NOW. DO IT.

 ==&gt;Download or listen to Security Catalyst #10 here (28 minutes long) &lt; ==

On This  Episode
The Windows WMF &quot;Zero-Day Exploit&quot;
We quickly explain the concepts behind &quot;zero-day&quot; attacks and exploits and the describe the current problem, as well as immediate steps you should take to protect yourself and your organization. 

Here are some links with detailed information you can use to help protect yourself:
F-Secure Weblog
Workaround, Protections Emerge for WMF Exploit
Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution - MICROSOFT
US-CERT: Vulnerability Note VU#181038

The Proposed SONY-BMG Settlement
The proposed settlement for CONSUMERS is interesting - and we take a look at the impact this may have to the long-term health of SONY-BMG, as well as what it may mean as a trend for corporate accountability.

2005 in Review - and what to do with this knowledge!
Rather than just recap some of the top trends, we go a bit deeper and look at what it means for those of us in the trenches - and what we might be doing about it next year. Even though some of the trends are negative, the results I found to be quite promising -- especially as we look forward to an exciting and productive 2006.


Have a safe and Happy New Year!</itunes:summary>
		<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
		<itunes:explicit>clean</itunes:explicit>
	</item>
	</channel>
</rss>
